DirectorySecurity Advisories
Sign In
Security Advisories

CGA-xj3j-mpx5-5qc8

Published

Last updated

https://images.chainguard.dev/security/CGA-xj3j-mpx5-5qc8
Package

croc

Latest Update
Fixed
Fixed Version

10.0.0-r0

Aliases
  • CVE-2023-43620
  • GHSA-364c-vvqx-446c

Severity

7.8

High

CVSS V3

Summary

Croc sender may place ANSI or CSI escape sequences in filename to attach receiver's terminal device

Description

An issue was discovered in Croc before 9.6.16. A sender may place ANSI or CSI escape sequences in a filename to attack the terminal device of a receiver.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images