在 lrzsz 0.13.0 之前的版本中,lrz 的接收工具在管道模式下存在操作系统命令注入漏洞。远程发送者可以通过提供精心构造的文件名来执行命令。当 lrz 以下列后缀名称运行时(例如 lrztar),src/lrz.c 中的 procheader() 函数会将未经转义的 ZMODEM/YMODEM 文件名传递给 popen(),导致 shell 元字符以接收用户的身份执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105840 | 7.5 HIGH | lrzsz before 0.13.0 Path Traversal via lrz Restricted Mode checkpath() |
| CVE-2026-105842 | 6.4 MEDIUM | lrzsz before 0.13.0 Heap Buffer Overflow via lrz procheader() Pathname |
No comments yet