CVE-2017-16034
Command Injection in pidusage
描述
Affected versions of `pidusage` pass unsanitized input to `child_process.exec()`, resulting in arbitrary code execution in the `ps` method. This package is vulnerable to this PoC on Darwin, SunOS, FreeBSD, and AIX. Windows and Linux are not vulnerable. ## Proof of Concept ``` var pid = require('pidusage'); pid.stat('1 && /usr/local/bin/python'); ``` ## Recommendation Update to version 1.1.5 or later.
如何修補 CVE-2017-16034
要修補 CVE-2017-16034,請將受影響套件升級到下列已修補版本。
- npm/pidusage—升級至 1.1.5 或更新版本
CVE-2017-16034 正在被利用嗎?
目前沒有被利用訊號。CVE-2017-16034 既不在 CISA KEV 也沒有最新的 EPSS 分數。
受影響套件(1)
- from 0, < 1.1.5