漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files within an archive that have relative or absolute file paths. A developer using the "tarExtract" function may expect that the function will strip leading slashes from absolute paths or stop processing when encountering relative paths that are outside of the extraction path, unless otherwise forced. This could lead to unexpected and undocumented behavior, which in general could result in a directory traversal, and associated unexpected behavior.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Wind River VxWorks 路径遍历漏洞
Vulnerability Description
Wind River VxWorks是美国风河系统(Wind River)公司的一个操作系统。用于构建嵌入式设备和系统的业界领先的实时操作系统。 Wind River VxWorks 存在安全漏洞,该漏洞源于 tarExtract 函数存在缺陷可能会导致意外和未记录的行为。
CVSS Information
N/A
Vulnerability Type
N/A