Source: miller
Version: 5.9.0-1
Severity: grave
Tags: security upstream
X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org>

Hi,

The following vulnerability was published for miller.

CVE-2020-15167[0]:
| In Miller (command line utility) using the configuration file support
| introduced in version 5.9.0, it is possible for an attacker to cause
| Miller to run arbitrary code by placing a malicious `.mlrrc` file in
| the working directory. See linked GitHub Security Advisory for
| complete details. A fix is ready and will be released as Miller 5.9.1.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2020-15167
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15167
[1] https://github.com/johnkerl/miller/security/advisories/GHSA-mw2v-4q78-j2cw

Regards,
Salvatore

Reply via email to