漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Ghidra Swift Demangler Analyzer Arbitrary Code Execution via Project State
Vulnerability Description
Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. When a victim opens the attacker-supplied project, SwiftDemanglerAnalyzer restores the persisted Swift binary directory from project state and SwiftNativeDemangler executes the resolved binary without integrity or signature verification, causing attacker-controlled executables to run under the Ghidra process user with no prompt or confirmation.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
对搜索路径元素未加控制
Vulnerability Title
National Security Agency ghidra software reverse engineering framework 权限许可和访问控制问题漏洞
Vulnerability Description
National Security Agency Ghidra Software Reverse Engineering Framework是美国National Security Agency政府部门开源的一个软件逆向工程框架。 National Security Agency ghidra software reverse engineering framework 12.1.2之前版本存在权限许可和访问控制问题漏洞,该漏洞源于Swift demangler分析器恢复Swift二进制目录后未进行完整性
CVSS Information
N/A
Vulnerability Type
N/A