picklescan before 0.0.25 fails to detect malicious pickle files that use timeit.timeit() in the __reduce__ method, allowing remote code execution. Attackers can craft pickle files that import dangerous libraries like os and execute arbitrary system commands, which evade picklescan detection and execute when pickle.load() is called.
picklescan before 0.0.25 fails to detect malicious pickle files that use timeit.timeit() in the reduce method, allowing remote code execution. Attackers can craft pickle files that import dangerous libraries like os and execute arbitrary system commands, which evade picklescan detection and execute when pickle.load() is called.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도 | 76.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 76.00 |
VPI 공식 vpi-v1 기준