漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
gpsd gpsprof Code Injection via SKY.satellites used Field
Vulnerability Description
gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot heredoc data block. Attackers can supply a used value containing the string EOD to terminate the heredoc early and append gnuplot system() calls, achieving OS command execution as the user running gpsprof when the generated plot script is processed by gnuplot in polar mode.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
gpsd project gpsd 代码注入漏洞
Vulnerability Description
gpsd project gpsd是gpsd project团队开源的一个GPS数据接收守护程序。 gpsd project gpsd 3.27.5及之前版本存在代码注入漏洞,该漏洞源于gpsprof工具存在OS命令注入,gpsd将未经验证的GPS输入数据插入到gnuplot heredoc数据块中,攻击者可以通过注入恶意内容到SKY.satellites[].used字段,利用包含EOD字符串的used值提前终止heredoc并添加gnuplot system()调用,当生成的绘图脚本在polar模式下
CVSS Information
N/A
Vulnerability Type
N/A