Escargot v4.3.0-214-gfaee4437 ... Note

Escargot v4.3.0-214-gfaee4437 OS Command Injection in Crash Handler via Unsanitized Executable Path

Posted by Ron E on Aug 26An OS command injection vulnerability exists in the Escargot v4.3.0-214-gfaee4437 crash handler due to an executable/module path being incorporated into an addr2line shell command without quoting or escaping. The resulting command is executed using system(), causing shell metacharacters contained within the path to be interpreted as command syntax. By launching Escargot using a crafted executable path containing shell metacharacters and...