漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
uutils coreutils printenv Security Inspection Bypass via UTF-8 Enforcement
Vulnerability Description
The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences. While POSIX permits arbitrary bytes in environment strings, the uutils implementation silently skips these entries rather than printing the raw bytes. This vulnerability allows malicious environment variables (e.g., adversarial LD_PRELOAD values) to evade inspection by administrators or security auditing tools, potentially allowing library injection or other environment-based attacks to go undetected.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
对因果或异常条件的不恰当检查
Vulnerability Title
uutils coreutils 代码问题漏洞
Vulnerability Description
uutils coreutils是Uutils开源的一个跨平台核心命令行工具集。 uutils coreutils存在代码问题漏洞,该漏洞源于printenv无法显示包含无效UTF-8字节序列的环境变量,可能导致恶意环境变量逃避管理员或安全审计工具检查。
CVSS Information
N/A
Vulnerability Type
N/A