Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2026-35366

4 месяца назад

The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences. While POSIX permits arbitrary bytes in environment strings, the uutils implementation silently skips these entries rather than printing the raw bytes. This vulnerability allows malicious environment variables (e.g., adversarial LD_PRELOAD values) to evade inspection by administrators or security auditing tools, potentially allowing library injection or other environment-based attacks to go undetected.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2026-35366

4 месяца назад

The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences. While POSIX permits arbitrary bytes in environment strings, the uutils implementation silently skips these entries rather than printing the raw bytes. This vulnerability allows malicious environment variables (e.g., adversarial LD_PRELOAD values) to evade inspection by administrators or security auditing tools, potentially allowing library injection or other environment-based attacks to go undetected.

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2026-35366

4 месяца назад

The printenv utility in uutils coreutils fails to display environment ...

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-p7h3-7q52-72w8

около 1 месяца назад

printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-35366

The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences. While POSIX permits arbitrary bytes in environment strings, the uutils implementation silently skips these entries rather than printing the raw bytes. This vulnerability allows malicious environment variables (e.g., adversarial LD_PRELOAD values) to evade inspection by administrators or security auditing tools, potentially allowing library injection or other environment-based attacks to go undetected.

CVSS3: 4.4
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-35366

The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences. While POSIX permits arbitrary bytes in environment strings, the uutils implementation silently skips these entries rather than printing the raw bytes. This vulnerability allows malicious environment variables (e.g., adversarial LD_PRELOAD values) to evade inspection by administrators or security auditing tools, potentially allowing library injection or other environment-based attacks to go undetected.

CVSS3: 4.4
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-35366

The printenv utility in uutils coreutils fails to display environment ...

CVSS3: 4.4
0%
Низкий
4 месяца назад
github логотип
GHSA-p7h3-7q52-72w8

printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)

CVSS3: 4.4
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу