Candidate: CVE-2020-15167 PublicDate: 2020-09-02 18:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15167 https://github.com/johnkerl/miller/security/advisories/GHSA-mw2v-4q78-j2cw Description: In Miller (command line utility) using the configuration file support introduced in version 5.9.0, it is possible for an attacker to cause Miller to run arbitrary code by placing a malicious `.mlrrc` file in the working directory. See linked GitHub Security Advisory for complete details. A fix is ready and will be released as Miller 5.9.1. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H [8.6 HIGH] Patches_miller: upstream_miller: needs-triage precise/esm_miller: DNE trusty_miller: ignored (out of standard support) trusty/esm_miller: DNE xenial_miller: ignored (end of standard support, was needs-triage) bionic_miller: needs-triage focal_miller: needs-triage groovy_miller: ignored (reached end-of-life) hirsute_miller: not-affected (5.9.1+dfsg-1) impish_miller: not-affected (5.9.1+dfsg-1) jammy_miller: not-affected (5.9.1+dfsg-1) devel_miller: not-affected (5.9.1+dfsg-1)