Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Calibre 安全漏洞
Vulnerability Description
Calibre是一套免费的、开源的电子图书管理软件。该软件可提供对图书进行格式转换和归类整理电子书等功能。 Calibre 3.18版本中的gui2/viewer/bookmarkmanager.py文件存在安全漏洞。远程攻击者可借助特制的.pickle文件利用该漏洞执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A