{"id":"CVE-2024-38448","details":"htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may be used.","modified":"2026-01-27T04:19:40.380758Z","published":"2024-06-16T14:15:09Z","withdrawn":"2026-01-27T04:19:40.380758Z","related":["openSUSE-SU-2024:0210-1","openSUSE-SU-2024:14123-1"],"references":[{"type":"WEB","url":"https://cvs.savannah.gnu.org/viewvc/global/global/htags/htags.c?revision=1.236&view=markup"},{"type":"WEB","url":"https://lists.gnu.org/archive/html/bug-global/2024-05/msg00009.html"}],"schema_version":"1.7.3"}