HIGH7.8
GHSA-364c-vvqx-446c
Croc sender may place ANSI or CSI escape sequences in filename to attach receiver's terminal device
Quick fix
GHSA-364c-vvqx-446c — github.com/schollz/croc/v9: upgrade to the fixed version with the command below.
go get github.com/schollz/croc/v9@v9.6.16Details
An issue was discovered in Croc before 9.6.16. A sender may place ANSI or CSI escape sequences in a filename to attack the terminal device of a receiver.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/schollz/croc/v9
Introduced in:
0Fixed in: 9.6.16Fix
go get github.com/schollz/croc/v9@v9.6.16References
- https://nvd.nist.gov/vuln/detail/CVE-2023-43620[ADVISORY]
- https://github.com/schollz/croc/issues/595[WEB]
- https://github.com/schollz/croc/pull/697[WEB]
- https://github.com/schollz/croc/commit/3f12f75fae2e844c555ec01eeba0b8474938e93a[WEB]
- https://github.com/schollz/croc[PACKAGE]
- https://www.openwall.com/lists/oss-security/2023/09/08/2[WEB]
- http://www.openwall.com/lists/oss-security/2023/09/21/5[WEB]