CVE-2024-27629

June 28, 2024, 7:15 p.m.

None
No Score

Description

An issue in dc2niix before v.1.0.20240202 allows a local attacker to execute arbitrary code via the generated file name is not properly escaped and injected into a system call when certain types of compression are used.

Product(s) Impacted

Product Versions
dc2niix
  • ['before v.1.0.20240202']

Weaknesses

Common security weaknesses mapped to this vulnerability.

Timeline

Published: June 28, 2024, 7:15 p.m.
Last Modified: June 28, 2024, 7:15 p.m.

Status : Received

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

cve@mitre.org

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.