Описание
A flaw was found in svxlink's reflector client. The talker_start and talker_stop event handlers directly concatenate a server-supplied talker callsign into Tcl_Eval commands without any sanitization or escaping. A malicious or compromised reflector server can supply a crafted callsign containing TCL metacharacters to achieve arbitrary OS command execution with the privileges of the svxlink process.
Отчет
svxlink is not shipped in any Red Hat Enterprise product. It is available in Fedora as a community-maintained package.
Меры по смягчению последствий
Update svxlink to version 26.05.1 or later.
Дополнительная информация
Статус:
Important
Дефект:
CWE-95
https://bugzilla.redhat.com/show_bug.cgi?id=2513802svxlink: svxlink: Remote code execution via TCL command injection in reflector client