Junglewise Threat Intelligence

CVE-2023-43620: GO-2023-2068 - Croc sender may place ANSI or CSI escape sequences in filename to attach receiver's terminal device in github.com/schollz/croc

CVE-2023-43620 · Severity: low · CVSS 3.1 · Published 2024-08-21

Technologies: github.com/schollz/croc/v8 (Go), github.com/schollz/croc/v9 (Go), github.com/schollz/croc (Go), github.com/schollz/croc/v6 (Go). Vendors: Go.

Executive brief

Croc sender may place ANSI or CSI escape sequences in filename to attach receiver's terminal device in github.com/schollz/croc

Affected products

  • Go github.com/schollz/croc/v8
  • Go github.com/schollz/croc/v9
  • Go github.com/schollz/croc
  • Go github.com/schollz/croc/v6

Related threats