漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Fickling has Code Injection vulnerability via pty.spawn()
Vulnerability Description
Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missing from the block list of unsafe module imports. This led to unsafe pickles based on `pty.spawn()` being incorrectly flagged as `LIKELY_SAFE`, and was fixed in version 0.1.6. This impacted any user or system that used Fickling to vet pickle files for security issues.
CVSS Information
N/A
Vulnerability Type
不完整的黑名单
Vulnerability Title
Fickling 代码问题漏洞
Vulnerability Description
Fickling是Trail of Bits开源的一个Python的反编译器和静态分析器。 Fickling 0.1.6之前版本存在代码问题漏洞,该漏洞源于缺少pty模块的安全检查,可能导致执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A