collectl 4.3.20.2 之前的版本中,colmux 组件在显示从远程 collectl 实例接收的数据时,未对 ANSI/VT100 终端转义序列进行清理。这使得被监控主机上的本地用户能够通过构造特定的进程名称(argv[0]),向正在运行 colmux 的操作员终端注入转义序列,从而可能执行恶意操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | - | 0 ~ 4.3.20.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet