SLRN Arbitrary Shell Script...

- AV AC AU C I A
发布: 2001-09-24
修订: 2025-04-13

slrn is a freely available NTTP reader by Thomas Schultz. It is maintained and developed by the slrn project. A problem in the program has been discovered that could allow arbitrary command execution. When a user of slrn downloads a post with a binary contained, slrn will execute any shell script contained in the post included with the binary. This could lead to arbitrary command execution, and a remote user gaining access to the system with the privileges of the slrn user. This is currently known to affect only Debian Linux.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息