egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .egg file.
{ "binaries": [ { "binary_name": "chicken-bin", "binary_version": "5.2.0-2" }, { "binary_name": "libchicken-dev", "binary_version": "5.2.0-2" }, { "binary_name": "libchicken11", "binary_version": "5.2.0-2" } ] }
{ "binaries": [ { "binary_name": "chicken-bin", "binary_version": "5.3.0-1.1build1" }, { "binary_name": "libchicken-dev", "binary_version": "5.3.0-1.1build1" }, { "binary_name": "libchicken11t64", "binary_version": "5.3.0-1.1build1" } ] }
{ "binaries": [ { "binary_name": "chicken-bin", "binary_version": "5.3.0-2" }, { "binary_name": "libchicken-dev", "binary_version": "5.3.0-2" }, { "binary_name": "libchicken11t64", "binary_version": "5.3.0-2" } ] }
{ "binaries": [ { "binary_name": "chicken-bin", "binary_version": "4.9.0.1-1" }, { "binary_name": "libchicken-dev", "binary_version": "4.9.0.1-1" }, { "binary_name": "libchicken7", "binary_version": "4.9.0.1-1" } ] }
{ "binaries": [ { "binary_name": "chicken-bin", "binary_version": "4.12.0-0.3" }, { "binary_name": "libchicken-dev", "binary_version": "4.12.0-0.3" }, { "binary_name": "libchicken8", "binary_version": "4.12.0-0.3" } ] }
{ "binaries": [ { "binary_name": "chicken-bin", "binary_version": "5.1.0-1" }, { "binary_name": "libchicken-dev", "binary_version": "5.1.0-1" }, { "binary_name": "libchicken11", "binary_version": "5.1.0-1" } ] }