The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via shell metacharacters in a file name.
| Software | From | Fixed in |
|---|---|---|
| selinux / setroubleshoot | - | 3.2.21.x |
| fedoraproject / fedora | 22 | 22.x |