Debian R-Base vulnerabilities
4 known vulnerabilities affecting debian/r-base.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1LOW2
Vulnerabilities
Page 1 of 1
CVE-2024-27322LOWCVSS 8.8fixed in r-base 4.4.0-2 (forky)2024
CVE-2024-27322 [HIGH] CVE-2024-27322: r-base - Deserialization of untrusted data can occur in the R statistical programming lan...
Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0, enabling a maliciously crafted RDS (R Data Serialization) formatted file or R package to run arbitrary code on an end user’s system when interacted with.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixe
debian
CVE-2020-27637CRITICALCVSS 9.8fixed in r-base 4.0.3-1 (bookworm)2020
CVE-2020-27637 [CRITICAL] CVE-2020-27637: r-base - The R programming language’s default package manager CRAN is affected by a path ...
The R programming language’s default package manager CRAN is affected by a path traversal vulnerability that can lead to server compromise. This vulnerability affects packages installed via the R CMD install cli command or the install.packages() function from the interpreter. Update to version 4.0.3
Scope: local
bookworm: resolved (fixed in 4.0.3-1)
bullseye: res
debian
CVE-2016-8714HIGHCVSS 8.8fixed in r-base 3.3.3-1 (bookworm)2016
CVE-2016-8714 [HIGH] CVE-2016-8714: r-base - An exploitable buffer overflow vulnerability exists in the LoadEncoding function...
An exploitable buffer overflow vulnerability exists in the LoadEncoding functionality of the R programming language version 3.3.0. A specially crafted R script can cause a buffer overflow resulting in a memory corruption. An attacker can send a malicious R script to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 3.3.3-1)
bullseye: resolved (fixed
debian
CVE-2008-3931LOWCVSS 6.9fixed in r-base 2.7.2-1 (bookworm)2008
CVE-2008-3931 [MEDIUM] CVE-2008-3931: r-base - javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a syml...
javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Scope: local
bookworm: resolved (fixed in 2.7.2-1)
bullseye: resolved (fixed in 2.7.2-1)
forky: resolved (fixed in 2.7.2-1)
sid: resolved (fixed in 2.7.2-1)
trixie: resolved (fixed in 2.7.2-1)
debian