CVE-2023-38198

NameCVE-2023-38198
Descriptionacme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
acme.sh (PTS)trixie3.1.1-1fixed
forky, sid3.1.2+~cs0.0.20251126-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
acme.shsource(unstable)(not affected)

Notes

- acme.sh <not-affected> (Fixed before initial upload to the archive)

Search for package or bug name: Reporting problems