ack 2.00 through 2.11_02 allows remote attackers to execute arbitrary code via a (1) --pager, (2) --regex, or (3) --output option in a .ackrc file in a directory to be searched.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| beyondgrep | ack | 2.11_02 |
| beyondgrep | ack | 2.05_01 |
| beyondgrep | ack | 2.04 |
| beyondgrep | ack | 2.06 |
| beyondgrep | ack | 2.08 |
| beyondgrep | ack | 2.11_01 |
| beyondgrep | ack | 2.11 |
| beyondgrep | ack | 2.02 |
| beyondgrep | ack | 2.10 |
| beyondgrep | ack | 2.00 |