Описание
The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| rust-shlex | fixed | 1.3.0-1 | package | |
| rust-shlex | no-dsa | bookworm | package | |
| rust-shlex | no-dsa | bullseye | package | |
| rust-shlex | no-dsa | buster | package |
Примечания
https://rustsec.org/advisories/RUSTSEC-2024-0006.html
https://github.com/comex/rust-shlex/security/advisories/GHSA-r7qv-8r2h-pg27
EPSS
Связанные уязвимости
The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.
The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.
The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.
The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.
EPSS