chainguard-dev / bincapz

detect malicious program behaviors
Apache License 2.0
378 stars 24 forks source link

probable-false: techniques/code_eval in gawk-5.3 ($at_eval) #290

Closed tstromberg closed 1 day ago

tstromberg commented 1 week ago
packages/x86_64/gawk-5.3/usr/bin/awk [🚨 CRITICAL]
--------------------------------------------------------------------------------------
RISK  KEY                   DESCRIPTION                                     EVIDENCE  
--------------------------------------------------------------------------------------
CRIT  techniques/code_eval  evaluates code in a way that suppresses errors  $at_eval  
--------------------------------------------------------------------------------------