egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .egg file.
{ "binaries": [ { "binary_version": "4.9.0.1-1", "binary_name": "chicken-bin" }, { "binary_version": "4.9.0.1-1", "binary_name": "libchicken-dev" }, { "binary_version": "4.9.0.1-1", "binary_name": "libchicken7" } ] }
{ "binaries": [ { "binary_version": "4.12.0-0.3", "binary_name": "chicken-bin" }, { "binary_version": "4.12.0-0.3", "binary_name": "libchicken-dev" }, { "binary_version": "4.12.0-0.3", "binary_name": "libchicken8" } ] }
{ "binaries": [ { "binary_version": "5.1.0-1", "binary_name": "chicken-bin" }, { "binary_version": "5.1.0-1", "binary_name": "libchicken-dev" }, { "binary_version": "5.1.0-1", "binary_name": "libchicken11" } ] }
{ "binaries": [ { "binary_version": "5.2.0-2", "binary_name": "chicken-bin" }, { "binary_version": "5.2.0-2", "binary_name": "libchicken-dev" }, { "binary_version": "5.2.0-2", "binary_name": "libchicken11" } ] }
{ "binaries": [ { "binary_version": "5.3.0-1.1build1", "binary_name": "chicken-bin" }, { "binary_version": "5.3.0-1.1build1", "binary_name": "libchicken-dev" }, { "binary_version": "5.3.0-1.1build1", "binary_name": "libchicken11t64" } ] }
{ "binaries": [ { "binary_version": "5.3.0-2", "binary_name": "chicken-bin" }, { "binary_version": "5.3.0-2", "binary_name": "libchicken-dev" }, { "binary_version": "5.3.0-2", "binary_name": "libchicken11t64" } ] }