VDB
CVE-2023-50255
CVE-2023-50255
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Deepin-Compressor is the default archive manager of Deepin Linux OS. Prior to 5.12.21, there's a path traversal vulnerability in deepin-compressor that can be exploited to achieve Remote Command Execution on the target system upon opening crafted archives. Users are advised to update to version 5.12.21 which addresses the issue. There are no known workarounds for this vulnerability.
EPSS 1.05% · 61.2th percentile
Risk Scores
CVSS 3.1
9.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
EPSS Score
1.05%
61.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| deepin | deepin-compressor | 0, 0 |
| linuxdeepin | developer-center | < 5.12.21, < 5.12.21 |
Timeline
- Jan 21, 1970 Security Advisory
- Dec 27, 2023 CVE Published
- Dec 27, 2023 PoC Published
- Dec 28, 2023 EPSS Score
- Jan 19, 2024 PoC Published
- Jan 26, 2024 EPSS Score
- Feb 24, 2024 EPSS Score
- Mar 23, 2024 EPSS Score
- Apr 21, 2024 EPSS Score
- May 20, 2024 EPSS Score
- Jun 18, 2024 EPSS Score
- Jul 16, 2024 EPSS Score