Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GNOME Eye Of Gnome文件名处理格式串漏洞
Vulnerability Description
Eye Of Gnome是一款图象查看器,是GNOME桌面包含的程序。 Eye Of Gnome对用户提供的文件名参数缺少正确检查,本地或远程攻击者可以提交包含恶意文件名的文件给EOG处理,导致发生堆破坏,可能以EOG进程权限在系统上执行任意指令。 EOG接收图象问名作为命令行参数,程序没有充分过滤参数数据,提供包含格式字符串的文件名可以破坏堆栈内容,精心提交文件名数据可能以EOG进程权限在系统上执行任意指令。
CVSS Information
N/A
Vulnerability Type
N/A