{"id":"CVE-2024-10224","details":"Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a \"pesky pipe\" (such as passing \"commands|\" as a filename) or by passing arbitrary strings to eval().","aliases":["GHSA-g597-359q-v529"],"modified":"2026-08-12T03:30:27.545790803Z","published":"2024-11-19T17:35:25.014Z","related":["ALSA-2025:7350","openSUSE-SU-2025:14635-1"],"database_specific":{"unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"1.38"}]}],"cna_assigner":"canonical","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/10xxx/CVE-2024-10224.json"},"references":[{"type":"WEB","url":"http://seclists.org/fulldisclosure/2024/Nov/15"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2024/Nov/17"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/11/msg00015.html"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2024/11/19/1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/10xxx/CVE-2024-10224.json"},{"type":"ADVISORY","url":"https://github.com/rschupp/Module-ScanDeps/security/advisories/GHSA-g597-359q-v529"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-10224"},{"type":"ADVISORY","url":"https://www.qualys.com/2024/11/19/needrestart/needrestart.txt"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2024-10224"},{"type":"PACKAGE","url":"https://github.com/rschupp/Module-ScanDeps"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rschupp/module-scandeps","events":[{"introduced":"0"},{"fixed":"e1f2e14c5bee4d78c94b0cddf120e81af104f6dd"}],"database_specific":{"cpe":"cpe:2.3:a:rschupp:modules\\:\\:scandeps:*:*:*:*:*:perl:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.36"}],"source":["DESCRIPTION","CPE_RANGE"]}}],"versions":["1.35","1.34","1.33","1.32","1.31","1.30","1.29","1.28","1.27","1.26","1.25","1.24","1.23","1.22"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-10224.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"}]}