Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when calling analyzeHeadless with untrusted input.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
NSA Ghidra 命令注入漏洞
Vulnerability Description
NSA Ghidra是美国国家安全局(National Security Agency)的一款开源逆向工程工具。 NSA Ghidra 10.2.2及以前的版本存在安全漏洞,该漏洞源于其Ghidra/RuntimeScripts/Linux/support/launch.sh文件将用户提供的输入传递给eval,当使用不可信的输入调用analyzeHeadless时,会导致命令注入。
CVSS Information
N/A
Vulnerability Type
N/A