Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0, enabling a maliciously crafted RDS (R Data Serialization) formatted file or R package to run arbitrary code on an end user’s system when interacted with.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "4.4.1-1", "binary_name": "r-base" }, { "binary_version": "4.4.1-1", "binary_name": "r-base-core" }, { "binary_version": "4.4.1-1", "binary_name": "r-base-core-dbgsym" }, { "binary_version": "4.4.1-1", "binary_name": "r-base-dev" }, { "binary_version": "4.4.1-1", "binary_name": "r-base-html" }, { "binary_version": "4.4.1-1", "binary_name": "r-doc-html" }, { "binary_version": "4.4.1-1", "binary_name": "r-doc-info" }, { "binary_version": "4.4.1-1", "binary_name": "r-doc-pdf" }, { "binary_version": "4.4.1-1", "binary_name": "r-mathlib" }, { "binary_version": "4.4.1-1", "binary_name": "r-mathlib-dbgsym" }, { "binary_version": "4.4.1-1", "binary_name": "r-recommended" } ] }