Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.
{ "binaries": [ { "binary_name": "freecad", "binary_version": "0.21.2+dfsg1-5" }, { "binary_name": "freecad-common", "binary_version": "0.21.2+dfsg1-5" }, { "binary_name": "freecad-python3", "binary_version": "0.21.2+dfsg1-5" }, { "binary_name": "freecad-python3-dbgsym", "binary_version": "0.21.2+dfsg1-5" }, { "binary_name": "libfreecad-python3-0.20", "binary_version": "0.21.2+dfsg1-5" }, { "binary_name": "libfreecad-python3-0.20-dbgsym", "binary_version": "0.21.2+dfsg1-5" } ], "availability": "No subscription required", "ubuntu_priority": "medium" }
{ "binaries": [ { "binary_name": "freecad", "binary_version": "1.0.0+dfsg-5build1" }, { "binary_name": "freecad-common", "binary_version": "1.0.0+dfsg-5build1" }, { "binary_name": "freecad-python3", "binary_version": "1.0.0+dfsg-5build1" }, { "binary_name": "freecad-python3-dbgsym", "binary_version": "1.0.0+dfsg-5build1" }, { "binary_name": "libfreecad-python3", "binary_version": "1.0.0+dfsg-5build1" }, { "binary_name": "libfreecad-python3-dbgsym", "binary_version": "1.0.0+dfsg-5build1" } ], "availability": "No subscription required", "ubuntu_priority": "medium" }