A vulnerability in the Guix package manager allows for remote code execution on the system.
Vulnerabilities (CVE not assigned) have been identified in the implementation of the internal command 'guix substitute' in the Guix package manager, which is automatically invoked by the background process guix-daemon during package installation operations. This command is used to download already built binary packages from external servers, checking their integrity using a digital signature. The most dangerous vulnerability allows remote code execution on the user's system […]
