Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An exploitable buffer overflow vulnerability exists in the tag parsing functionality of Ledger-CLI 3.1.1. A specially crafted journal file can cause an integer underflow resulting in code execution. An attacker can construct a malicious journal file to trigger this vulnerability.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ledger-CLI 缓冲区错误漏洞
Vulnerability Description
Ledger是由软件开发者John Wiegley编写的一套支持UNIX命令的会计系统。Ledger-CLI是其中的一个命令行程序。 Ledger-CLI 3.1.1版本中的tag解析功能存在缓冲区溢出漏洞。攻击者可借助特制的journal文件利用该漏洞执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A