Audit before 2.4.4 in Linux does not sanitize escape characters in filenames.
CVSS Details
- CVSS 3.0 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade audit | Jul 30, 2024 | Sep 6, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade audit-libs-pythonUpgrade audit-libsUpgrade audispd-pluginsUpgrade audit-libs-develUpgrade audit | Dec 4, 2019 | Sep 6, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade audit-libsUpgrade audispd-pluginsUpgrade audit-libs-develUpgrade audit-libs-pythonUpgrade audit | Dec 18, 2019 | Sep 6, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 13, 2015 |
| Suse | — | Upgrade python3-auditUpgrade libauparse0Upgrade auditUpgrade libaudit1-32bitUpgrade audit-audispd-pluginsUpgrade libaudit1Upgrade audit-develUpgrade python2-audit | May 20, 2018 | Sep 6, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Sep 6, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub