漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
picklescan - Scanning Bypass via Dynamic Eval in scan_pytorch
Vulnerability Description
picklescan before 1.0.3 contains a scanning bypass vulnerability in the scan_pytorch function that allows attackers to embed malicious magic numbers via dynamic eval using the __reduce__ trick. Attackers can craft malicious PyTorch payloads that evade picklescan detection while remaining executable, enabling arbitrary code execution when loaded with torch.load().
CVSS Information
N/A
Vulnerability Type
动态执行代码中指令转义处理不恰当(Eval注入)
Vulnerability Title
Matthieu Maitre Picklescan 代码注入漏洞
Vulnerability Description
Picklescan是美国Matthieu Maitre个人开发者的一款扫描Pickle文件安全风险的静态分析工具。 Matthieu Maitre Picklescan 1.0.3之前版本存在代码注入漏洞,该漏洞源于scan_pytorch函数中存在动态eval问题,可能导致攻击者利用__reduce__技巧嵌入恶意幻数,从而执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A