xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.
Get an AI-powered plain-language explanation of this vulnerability and remediation steps.
Login to generate AI explanation22 reference(s) from NVD