The REPL server (--listen) in GNU Guile 2.0.12 allows an attacker to execute arbitrary code via an HTTP inter-protocol attack.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade guile | Sep 20, 2017 | Jan 12, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 12, 2017 |
| Debian | — | Upgrade guile-2.0 | Mar 31, 2017 | Oct 18, 2016 |
| Freebsd | — | Upgrade guile2 | Feb 5, 2017 | Feb 4, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 11, 2016 |
| Suse | — | Upgrade guile-modules-2_0Upgrade guile-develUpgrade guileUpgrade libguile-2_0-22Upgrade libguilereadline-v-18-18 | Nov 3, 2016 | Oct 26, 2016 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jan 12, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub