Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory, which can be leveraged to conduct format string attacks.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ELinks 'loadmsgcat.c' 未信任搜索路径漏洞
Vulnerability Description
Elinks的intl/gettext/loadmsgcat.c中的add_filename_to_string函数存在未信任搜索路径漏洞。本地用户可以通过造成Elinks使用"../po""目录中的不可信的gettext通讯录,执行格式化字符串攻击。
CVSS Information
N/A
Vulnerability Type
N/A