VYPR
Critical severity9.8NVD Advisory· Published Feb 24, 2020· Updated Jun 17, 2026

CVE-2019-18182

CVE-2019-18182

Description

pacman before 5.2 is vulnerable to arbitrary command injection in conf.c in the download_with_xfercommand() function. This can be exploited when unsigned databases are used. To exploit the vulnerability, the user must enable a non-default XferCommand and retrieve an attacker-controlled crafted database and package.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:pacman_project:pacman:*:*:*:*:*:*:*:*
    Range: <5.2
  • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
  • pacman/pacmandescription
  • Archlinux/Pacmanllm-fuzzy
    Range: <5.2

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.