Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Buffer overflow in the environment variable substitution code in main.c in OSH 1.7-14 allows local users to inject arbitrary environment variables, such as LD_PRELOAD, via pathname arguments of the form "$VAR/EVAR=arg", which cause the EVAR portion to be appended to a buffer returned by a getenv function call.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mike Neuman OSH环境变量缓冲区溢出漏洞
Vulnerability Description
osh是一款用于限制用户操作行为的SHELL。 OSH 1.7-14的main.c中环境变量替换代码内的缓冲区溢出,可让本地用户通过""$VAR/EVAR=arg"形式(这会导致EVAR部分附加到由getenv函数调用返回的缓冲区中)的路径名参数注入任意环境变量,如LD_PRELOAD。
CVSS Information
N/A
Vulnerability Type
N/A