rpm package
opensuse/ack&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/ack&distro=openSUSE%20Tumbleweed
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-49147 | Hig | 7.5 | < 3.10.0-1.1 | 3.10.0-1.1 | Jul 8, 2026 | App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes. When ack prints a filename whose basename contains terminal control bytes such as ANSI escape sequences, those bytes reach the terminal unchanged. Versio | |
| CVE-2026-49146 | Hig | 7.5 | < 3.10.0-1.1 | 3.10.0-1.1 | Jul 8, 2026 | App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc. ack searches up the directory hierarchy from the current directory for a project .ackrc and loads its options. The -B and -C context options accepted any positive | |
| CVE-2026-49145 | Hig | 7.5 | < 3.10.0-1.1 | 3.10.0-1.1 | Jul 8, 2026 | App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up the directory hierarchy from the current directory for a project .ackrc and loads its options. The project-source option blocklist in App::Ack::ConfigLoader does | |
| CVE-2013-7069 | — | < 2.15_02-1.3 | 2.15_02-1.3 | Dec 14, 2013 | ack 2.00 through 2.11_02 allows remote attackers to execute arbitrary code via a (1) --pager, (2) --regex, or (3) --output option in a .ackrc file in a directory to be searched. |
- affected < 3.10.0-1.1fixed 3.10.0-1.1
App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes. When ack prints a filename whose basename contains terminal control bytes such as ANSI escape sequences, those bytes reach the terminal unchanged. Versio
- affected < 3.10.0-1.1fixed 3.10.0-1.1
App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc. ack searches up the directory hierarchy from the current directory for a project .ackrc and loads its options. The -B and -C context options accepted any positive
- affected < 3.10.0-1.1fixed 3.10.0-1.1
App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up the directory hierarchy from the current directory for a project .ackrc and loads its options. The project-source option blocklist in App::Ack::ConfigLoader does
- CVE-2013-7069Dec 14, 2013affected < 2.15_02-1.3fixed 2.15_02-1.3
ack 2.00 through 2.11_02 allows remote attackers to execute arbitrary code via a (1) --pager, (2) --regex, or (3) --output option in a .ackrc file in a directory to be searched.