Описание
[GHSA-pc2g-2p95-4cr5: TCL command injection in reflector client]
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| svxlink | fixed | 26.05.1-1 | package | |
| svxlink | no-dsa | trixie | package |
Примечания
https://github.com/sm0svx/svxlink/security/advisories/GHSA-pc2g-2p95-4cr5
Связанные уязвимости
redhat
около 2 месяцев назад
A flaw was found in svxlink's reflector client. The talker_start and talker_stop event handlers directly concatenate a server-supplied talker callsign into Tcl_Eval commands without any sanitization or escaping. A malicious or compromised reflector server can supply a crafted callsign containing TCL metacharacters to achieve arbitrary OS command execution with the privileges of the svxlink process.