Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
badkeys vulnerable to ASCII control character injection on console via malformed input
Vulnerability Description
badkeys is a tool and library for checking cryptographic public keys for known vulnerabilities. In versions 0.0.15 and below, an attacker may inject content with ASCII control characters like vertical tabs, ANSI escape sequences, etc., that can create misleading output of the badkeys command-line tool. This impacts scanning DKIM keys (both --dkim and --dkim-dns), SSH keys (--ssh-lines mode), and filenames in various modes. This issue is fixed in version 0.0.16.
CVSS Information
N/A
Vulnerability Type
转义、元或控制序列转义处理不恰当
Vulnerability Title
badkeys 安全漏洞
Vulnerability Description
badkeys是badkeys开源的一个检查加密公钥是否存在漏洞的工具库。 badkeys 0.0.15及之前版本存在安全漏洞,该漏洞源于攻击者可注入包含ASCII控制字符的内容,可能产生误导性输出。
CVSS Information
N/A
Vulnerability Type
N/A