The extractTree function in unADF allows remote attackers to execute arbitrary code via shell metacharacters in a directory name in an adf file.
| Software | From | Fixed in |
|---|---|---|
| unadf_project / unadf | 1.0 | 1.0.x |
| debian / debian_linux | 8.0 | 8.0.x |
| debian / debian_linux | 7.0 | 7.0.x |