Vulnerability Description
XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where "scontrol show hostname" is executed in the presence of a crafted SLURM_NODELIST environment variable.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://gist.github.com/aydinnyunus/40e1d8a3b529261ae654ff4891f1e192
- https://github.com/XPixelGroup/BasicSR/blob/master/basicsr/utils/dist_util.py#L4
FAQ
What is CVE-2024-27763?
CVE-2024-27763 is a vulnerability with a CVSS score of 5.3 (MEDIUM). XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where "scontrol show hostname" is executed in the presence of a crafted SLURM_NODELIST environment variable...
How severe is CVE-2024-27763?
CVE-2024-27763 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-27763?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.