VYPR

Arr-pm

by jordansissel

Source repositories

CVEs (1)

  • CVE-2022-39224Sep 21, 2022
    risk 0.00cvss epss 0.00

    Arr-pm is an RPM reader/writer library written in Ruby. Versions prior to 0.0.12 are subject to OS command injection resulting in shell execution if the RPM contains a malicious "payload compressor" field. This vulnerability impacts the `extract` and `files` methods of the…