High severity8.8NVD Advisory· Published Oct 3, 2016· Updated Jun 17, 2026
CVE-2016-1244
CVE-2016-1244
Description
The extractTree function in unADF allows remote attackers to execute arbitrary code via shell metacharacters in a directory name in an adf file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:a:unadf_project:unadf:1.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- tmp.tjjr.fi/0001-Fix-unsafe-extraction-by-using-mkdir-instead-of-shel.patchnvdPatchVendor Advisory
- bugs.debian.org/cgi-bin/bugreport.cginvdPatchThird Party AdvisoryVDB Entry
- www.debian.org/security/2016/dsa-3676nvdThird Party Advisory
- www.securityfocus.com/bid/93332nvd
- lists.debian.org/debian-lts-announce/2024/03/msg00015.htmlnvd
- security.gentoo.org/glsa/201804-20nvd
News mentions
0No linked articles in our index yet.