DEBIAN-CVE-2024-39835

Source
https://security-tracker.debian.org/tracker/CVE-2024-39835
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-39835.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2024-39835
Upstream
Published
2025-07-17T20:15:27.400Z
Modified
2026-04-28T20:28:14.613968Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A code injection vulnerability has been identified in the Robot Operating System (ROS) 'roslaunch' command-line tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability arises from the use of the eval() method to process user-supplied, unsanitized parameter values within the substitution args mechanism, which roslaunch evaluates before launching a node. This flaw allows attackers to craft and execute arbitrary Python code.

References

Affected packages

Debian:11 / ros-ros-comm

Package

Name
ros-ros-comm
Purl
pkg:deb/debian/ros-ros-comm?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.15.9+ds1-7
1.15.9+ds1-7+deb11u1
1.15.9+ds1-8
1.15.9+ds1-9
1.15.9+ds1-10
1.15.9+ds1-11
1.15.13+ds1-1
1.15.13+ds1-2
1.15.13+ds1-3
1.15.13+ds1-4
1.15.13+ds1-5
1.15.13+ds1-6
1.15.14+ds-1
1.15.14+ds-2
1.15.14+ds-3
1.15.14+ds-4
1.15.14+ds-5
1.15.15+ds-1
1.15.15+ds-2
1.16.0+ds-1
1.16.0+ds-2
1.16.0+ds-3
1.16.0+ds-3.1~exp1
1.16.0+ds-3.1
1.16.0+ds-4
1.16.0+ds-5
1.16.0+ds-6
1.17.0+ds-1
1.17.0+ds-2
1.17.4+ds-1
1.17.4+ds-2
1.17.4+ds-3
1.17.4+ds-4

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-39835.json"

Debian:12 / ros-ros-comm

Package

Name
ros-ros-comm
Purl
pkg:deb/debian/ros-ros-comm?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.15.15+ds-2
1.16.0+ds-1
1.16.0+ds-2
1.16.0+ds-3
1.16.0+ds-3.1~exp1
1.16.0+ds-3.1
1.16.0+ds-4
1.16.0+ds-5
1.16.0+ds-6
1.17.0+ds-1
1.17.0+ds-2
1.17.4+ds-1
1.17.4+ds-2
1.17.4+ds-3
1.17.4+ds-4

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-39835.json"

Debian:13 / ros-ros-comm

Package

Name
ros-ros-comm
Purl
pkg:deb/debian/ros-ros-comm?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.17.0+ds-2
1.17.4+ds-1
1.17.4+ds-2
1.17.4+ds-3
1.17.4+ds-4

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-39835.json"

Debian:14 / ros-ros-comm

Package

Name
ros-ros-comm
Purl
pkg:deb/debian/ros-ros-comm?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.17.0+ds-2
1.17.4+ds-1
1.17.4+ds-2
1.17.4+ds-3
1.17.4+ds-4

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-39835.json"