Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Question] 中科天齐Wukong(悟空)声称 rainbow fart 具有漏洞,请问这会影响用户吗? #356

Closed
gledos opened this issue Jun 6, 2021 · 1 comment

Comments

@gledos
Copy link

gledos commented Jun 6, 2021

中科天齐Wukong(悟空)声称 rainbow fart 具有漏洞,请问这会影响用户吗?

最后,确定了名为Rainbow Fart的扩展程序具有zip slip漏洞,该漏洞使攻击者可以覆盖受害者计算机上的任意文件,并获得远程执行代码权限。一个特殊制作的ZIP文件通过插件使用的“import-voice-package”端点发送,并被写入扩展的工作目录之外的位置。这种攻击可能被用来覆盖‘.Bashrc’并获得远程代码执行权限。

VSCode扩展发现新漏洞 代码安全检测防御软件威胁 - 中科天齐Wukong(悟空)

@SaekiRaku
Copy link
Owner

SaekiRaku commented Jun 6, 2021 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants