漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
calibre is vulnerable to arbitrary code execution when opening FB2 files
Vulnerability Description
calibre is an e-book manager. In versions 8.13.0 and prior, calibre does not validate filenames when handling binary assets in FB2 files, allowing an attacker to write arbitrary files on the filesystem when viewing or converting a malicious FictionBook file. This can be leveraged to achieve arbitrary code execution. This issue is fixed in version 8.14.0.
CVSS Information
N/A
Vulnerability Type
文件名或路径的外部可控制
Vulnerability Title
Calibre 安全漏洞
Vulnerability Description
Calibre是印度Kovid Goyal个人开发者的一个开源免费的全能电子书阅读管理与格式转换工具。 Calibre 8.13.0及之前版本存在安全漏洞,该漏洞源于处理FB2文件中的二进制资源时未验证文件名,可能导致任意文件写入和代码执行。
CVSS Information
N/A
Vulnerability Type
N/A