VendorsGNUm4all versions
Vulnerabilities

GNU m4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2008-1688
Unspecified vulnerability in GNU m4 before 1.4.11 might allow context-dependent attackers to execute arbitrary code, related to improper handling of filenames specified with the -F option. NOTE: it is not clear when this issue crosses privilege boundaries.
Published 2008-04-09 · Modified
7.5EPSS 0.030
CVE-2008-1687
The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.
Published 2008-04-09 · Modified
7.5EPSS 0.025