漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
Vulnerability Description
Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, both ctypes and pydoc modules aren't explicitly blocked. Even other existing pickle scanning tools (like picklescan) do not block pydoc.locate. Chaining these two together can achieve RCE while the scanner still reports the file as LIKELY_SAFE. This issue has been patched in version 0.1.7.
CVSS Information
N/A
Vulnerability Type
不完整的黑名单
Vulnerability Title
Fickling 代码问题漏洞
Vulnerability Description
Fickling是Trail of Bits开源的一个Python的反编译器和静态分析器。 Fickling 0.1.7之前版本存在代码问题漏洞,该漏洞源于未明确阻止ctypes和pydoc模块,可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A