croc: Arbitrary File Deletion via received filename, chainable to RCE (fixed in 11.0.3)

Posted by Souiri Anas on Aug 14

Hello,

This reports an arbitrary file deletion vulnerability in croc, the
end-to-end encrypted file transfer tool [1], which can be chained to
remote code execution on the receiving host. The issue is fixed in
croc 11.0.3 [5].

Affected / fixed
================

Product: croc (github.com/schollz/croc, Go) [1]
Affected: >= 10.0.13, <= 11.0.2
Fixed in: 11.0.3 (commit c0d51f0 [4], PR #1232 [3])
Type: CWE-73 (External Control of File Name...

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论