CVE-2016-10075Code Injection in Tqdm

Severity
7.8HIGHNVD
EPSS
0.1%
top 74.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 19
Latest updateMay 14

Description

The tqdm._version module in tqdm versions 4.4.1 and 4.10 allows local users to execute arbitrary code via a crafted repo with a malicious git log in the current working directory.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

PyPItqdm/tqdm4.4.14.11.2+1
debiandebian/tqdm< tqdm 4.11.2-1 (bookworm)
Debiantqdm/tqdm< 4.11.2-1+3
NVDtqdm_project/tqdm4.10, 4.4.1+1

🔴Vulnerability Details

3
GHSA
TDQM Arbitrary Code Execution2022-05-14
OSV
TDQM Arbitrary Code Execution2022-05-14
OSV
CVE-2016-10075: The tqdm2017-01-19

📋Vendor Advisories

1
Debian
CVE-2016-10075: tqdm - The tqdm._version module in tqdm versions 4.4.1 and 4.10 allows local users to e...2016

💬Community

2
Bugzilla
CVE-2016-10075 python-tqdm: insecure use of 'git log' command2017-01-02
Bugzilla
CVE-2016-10075 python-tqdm: insecure use of 'git log' command [fedora-all]2017-01-02