CRITICAL
pacman before 5.2 is vulnerable to arbitrary command injection in conf.c in the download_with_xfercommand() function
Published Feb 24, 2020
9.8
CRITICALCVSS 3.1
EPSS 3.67%
Description
pacman before 5.2 is vulnerable to arbitrary command injection in conf.c in the download_with_xfercommand() function. This can be exploited when unsigned databases are used. To exploit the vulnerability, the user must enable a non-default XferCommand and retrieve an attacker-controlled crafted database and package.
Affected products
No data.
Configuration 1
- < 5.2
Configuration 2
OR
- 30
- 31
- 32
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://git.archlinux.org/pacman.git/commit/?id=808a4f15ce82d2ed7eeb06de73d0f313620558ee x_refsource_MISCPatchThird Party Advisory
- https://git.archlinux.org/pacman.git/tree/src/pacman/conf.c?h=v5.1.3#n263 x_refsource_MISCExploitThird Party Advisory
- https://github.com/alpinelinux/alpine-secdb/blob/master/v3.11/community.yaml x_refsource_CONFIRMRelease NotesThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2TTUXXUW5OCOASIRMJK4RHEPLEA33Y6C/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K53C45EDWBU3UCN3IRIGR5EZUNWXS7BW/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KIDJ4XKBZRRVRFFGKUA3ZU6NFIP5JUG3/ vendor-advisoryx_refsource_FEDORA
| Link | Providers | Tags |
|---|---|---|
| https://git.archlinux.org/pacman.git/commit/?id=808a4f15ce82d2ed7eeb06de73d0f313620558ee | x_refsource_MISCPatchThird Party Advisory | |
| https://git.archlinux.org/pacman.git/tree/src/pacman/conf.c?h=v5.1.3#n263 | x_refsource_MISCExploitThird Party Advisory | |
| https://github.com/alpinelinux/alpine-secdb/blob/master/v3.11/community.yaml | x_refsource_CONFIRMRelease NotesThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2TTUXXUW5OCOASIRMJK4RHEPLEA33Y6C/ | vendor-advisoryx_refsource_FEDORA | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K53C45EDWBU3UCN3IRIGR5EZUNWXS7BW/ | vendor-advisoryx_refsource_FEDORA | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KIDJ4XKBZRRVRFFGKUA3ZU6NFIP5JUG3/ | vendor-advisoryx_refsource_FEDORA |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 24, 2020
Updated Aug 5, 2024
Reserved Oct 17, 2019
Link CVE-2019-18182
CISA Vulnrichment
Updated n/a