Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GNU C Library 输入验证错误漏洞
Vulnerability Description
GNU C Library(glibc,libc6)是一种按照LGPL许可协议发布的开源免费的C语言编译程序。 GNU C Library 2.21版本存在输入验证错误漏洞,该漏洞源于程序没有正确处理WRDE_NOCMD标记。攻击者可利用该漏洞执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A