SonarSource / argument-injection-vectors

A curated list of argument injection vectors
GNU General Public License v3.0
37 stars 3 forks source link

Add argument injections and library load for fakeroot #32

Open cosad3s opened 9 months ago

cosad3s commented 9 months ago

Reported on: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1054396

This package is present in lot of environments.

(Other fakeroot forks / variations are probably subjects to these injections.)

thomas-chauchefoin-sonarsource commented 9 months ago

Thank you! I'll keep it open for now, and merge it once I find a CVE or a write-up of an argument injection on fakeroot.