THREAT OPS › Threat News › Escargot v4.3.0-214-gfaee4437 OS Command Injection in Crash Handler via Unsanitized Executable Path
Escargot v4.3.0-214-gfaee4437 OS Command Injection in Crash Handler via Unsanitized Executable Path
<p>Posted by Ron E on Aug 26</p>An OS command injection vulnerability exists in the Escargot<br /> v4.3.0-214-gfaee4437 crash handler due to an executable/module path being<br /> incorporated into an addr2line shell command without quoting or escaping.<br /> The resulting command is executed using system(), causing shell<br /> metacharacters contained within the path to be interpreted as command<b
Original source: https://seclists.org/fulldisclosure/2026/Aug/108