Debian R-Base vulnerabilities

4 known vulnerabilities affecting debian/r-base.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1LOW2

Vulnerabilities

Page 1 of 1
CVE-2024-27322LOWCVSS 8.8fixed in r-base 4.4.0-2 (forky)2024
CVE-2024-27322 [HIGH] CVE-2024-27322: r-base - Deserialization of untrusted data can occur in the R statistical programming lan... Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0, enabling a maliciously crafted RDS (R Data Serialization) formatted file or R package to run arbitrary code on an end user’s system when interacted with. Scope: local bookworm: open bullseye: open forky: resolved (fixe
debian
CVE-2020-27637CRITICALCVSS 9.8fixed in r-base 4.0.3-1 (bookworm)2020
CVE-2020-27637 [CRITICAL] CVE-2020-27637: r-base - The R programming language’s default package manager CRAN is affected by a path ... The R programming language’s default package manager CRAN is affected by a path traversal vulnerability that can lead to server compromise. This vulnerability affects packages installed via the R CMD install cli command or the install.packages() function from the interpreter. Update to version 4.0.3 Scope: local bookworm: resolved (fixed in 4.0.3-1) bullseye: res
debian
CVE-2016-8714HIGHCVSS 8.8fixed in r-base 3.3.3-1 (bookworm)2016
CVE-2016-8714 [HIGH] CVE-2016-8714: r-base - An exploitable buffer overflow vulnerability exists in the LoadEncoding function... An exploitable buffer overflow vulnerability exists in the LoadEncoding functionality of the R programming language version 3.3.0. A specially crafted R script can cause a buffer overflow resulting in a memory corruption. An attacker can send a malicious R script to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 3.3.3-1) bullseye: resolved (fixed
debian
CVE-2008-3931LOWCVSS 6.9fixed in r-base 2.7.2-1 (bookworm)2008
CVE-2008-3931 [MEDIUM] CVE-2008-3931: r-base - javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a syml... javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files. Scope: local bookworm: resolved (fixed in 2.7.2-1) bullseye: resolved (fixed in 2.7.2-1) forky: resolved (fixed in 2.7.2-1) sid: resolved (fixed in 2.7.2-1) trixie: resolved (fixed in 2.7.2-1)
debian