CVE-2013-7069

medium
Published 2013-12-14 · Modified 2026-04-29
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

ack 2.00 through 2.11_02 allows remote attackers to execute arbitrary code via a (1) --pager, (2) --regex, or (3) --output option in a .ackrc file in a directory to be searched.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — http://secunia.com/advisories/55982

Application impact

VendorProductVersionsFixed
beyondgrepack2.00
beyondgrepack2.02
beyondgrepack2.04
beyondgrepack2.05_01
beyondgrepack2.06
beyondgrepack2.08
beyondgrepack2.10
beyondgrepack2.11
beyondgrepack2.11_01
beyondgrepack2.11_02

References

CWEs

CWE-94

Verify integrity in audit chain (admin only). AS-IS.