CVE-2024-27322 Information
May 04, 2024
cve
Description
Deserialization of untrusted data can occur in the R statistical programming language on any version starting at 1.4.0 up to and not including 4.4.0 enabling a maliciously crafted RDS (R Data Serialization) formatted file or R package to run arbitrary code on an end user’s system when interacted with.
Reference
https://hiddenlayer.com/research/r-bitrary-code-execution/ https://https://kb.cert.org/vuls/id/238194 https://www.kb.cert.org/vuls/id/238194 http://www.openwall.com/lists/oss-security/2024/04/29/3
Share on: