Field Assessment
AI analysis pending.
CVE
CVE-2005-0638
Severity
HIGH
CVSS
7.5
EPSS
3.60%
Original Filing — NVD Description
xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.