Back to Database
Status published
Medium
CVE-2013-1874
Untrusted search path vulnerability in csi in Chicken before 4.8.2...
Vulnerability Description
Untrusted search path vulnerability in csi in Chicken before 4.8.2 allows local users to execute arbitrary code via a Trojan horse .csirc in the current working directory.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-1874
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.osvdb.org/91520
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85065
- http://code.call-cc.org/cgi-bin/gitweb.cgi?p=chicken-core.git%3Ba=blob%3Bf=NEWS%3Bh=c21c7cf9d1faf4f78736890ac7ca1d4b82d72ddd%3Bhb=c6750af99ada7fa4815ee834e4e705bcfac9c137
- http://www.securityfocus.com/bid/58583
- http://seclists.org/oss-sec/2013/q1/692
More from call-cc
View All →CVE-2022-45145
egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command...
Unknown
0
CVE-2017-9334
An incorrect "pair?" check in the Scheme "length" procedure results...
High
7.5
CVE-2017-6949
An issue was discovered in CHICKEN Scheme through 4.12.0. When...
High
8.1
CVE-2017-11343
Due to an incomplete fix for CVE-2012-6125, all versions of...
High
7.5
CVE-2016-6831
The "process-execute" and "process-spawn" procedures did not free memory correctly...
High
7.5
Affected Vendor
call-cc
View all reports →Affected Software
chicken
Vulnerable Versions:
0, 4.8.0, 4.8.0.1, 4.8.0.2, 4.8.0.3, 4.8.0.4, 4.8.0.5, 4.8.0.6, 4.8.0.7
Timeline
Official Publish:
September 29th, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.