Ubuntu Security Notice 255-1...

- AV AC AU C I A
发布: 2006-02-22
修订: 2025-04-13

Ubuntu Security Notice USN-255-1 - Tomas Mraz discovered a shell code injection flaw in scp. When doing local-to-local or remote-to-remote copying, scp expanded shell escape characters. By tricking an user into using scp on a specially crafted file name (which could also be caught by using an innocuous wild card like '*'), an attacker could exploit this to execute arbitrary shell commands with the privilege of that user.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息