Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vxqx-fgx3-fgh9

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The filecopy function in misc.c in Clam AntiVirus (ClamAV) before 0.85, on Mac OS, allows remote attackers to execute arbitrary code via a virus in a filename that contains shell metacharacters, which are not properly handled when HFS permissions prevent the file from being deleted and ditto is invoked.

The filecopy function in misc.c in Clam AntiVirus (ClamAV) before 0.85, on Mac OS, allows remote attackers to execute arbitrary code via a virus in a filename that contains shell metacharacters, which are not properly handled when HFS permissions prevent the file from being deleted and ditto is invoked.

EPSS

Процентиль: 84%
0.02166
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 20 лет назад

The filecopy function in misc.c in Clam AntiVirus (ClamAV) before 0.85, on Mac OS, allows remote attackers to execute arbitrary code via a virus in a filename that contains shell metacharacters, which are not properly handled when HFS permissions prevent the file from being deleted and ditto is invoked.

EPSS

Процентиль: 84%
0.02166
Низкий

Дефекты

CWE-20