Skip to content

Commit

Permalink
security/vuxml: Document ACE vulnerability in math/R
Browse files Browse the repository at this point in the history
In versions released before 4.4.0, the R statistical program is
vulnerable to CVE-2024-27322, which allows maliciously crafted RDS (R
Data Serialization) files or R packages to run arbitrary code.

Sponsored by:	The FreeBSD Foundation
  • Loading branch information
Jehops committed May 2, 2024
1 parent 2a131a9 commit f237383
Showing 1 changed file with 26 additions and 0 deletions.
26 changes: 26 additions & 0 deletions security/vuxml/vuln/2024.xml
Original file line number Diff line number Diff line change
@@ -1,3 +1,29 @@
<vuln vid="4a1e2bad-0836-11ef-9fd2-1c697a616631">
<topic>R -- arbitrary code execution vulnerability</topic>
<affects>
<package>
<name>R</name>
<range><lt>4.4.0</lt></range>
</package>
</affects>
<description>
<body xmlns="http://www.w3.org/1999/xhtml">
<p>HiddenLayer Research reports:</p>
<blockquote cite="https://hiddenlayer.com/research/r-bitrary-code-execution/">
<p>Deserialization of untrusted data can occur in the R statistical programming language, enabling a maliciously crafted RDS (R Data Serialization) formatted file or R package to run arbitrary code on an end user's system.</p>
</blockquote>
</body>
</description>
<references>
<cvename>CVE-2024-27322</cvename>
<url>https://nvd.nist.gov/vuln/detail/CVE-2024-27322</url>
</references>
<dates>
<discovery>2024-04-29</discovery>
<entry>2024-05-02</entry>
</dates>
</vuln>

<vuln vid="da4adc02-07f4-11ef-960d-5404a68ad561">
<topic>hcode -- buffer overflow in mail.c</topic>
<affects>
Expand Down

0 comments on commit f237383

Please sign in to comment.