VYPR
Critical severity9.8NVD Advisory· Published Feb 24, 2020· Updated Jun 17, 2026

CVE-2019-18183

CVE-2019-18183

Description

pacman before 5.2 is vulnerable to arbitrary command injection in lib/libalpm/sync.c in the apply_deltas() function. This can be exploited when unsigned databases are used. To exploit the vulnerability, the user must enable the non-default delta feature and retrieve an attacker-controlled crafted database and delta file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:pacman_project:pacman:*:*:*:*:*:*:*:*
    Range: <5.2
  • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
  • pacman/pacmandescription
  • Archlinux/Pacmanllm-fuzzy
    Range: <5.2

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.