uu_kill is vulnerable to Improper Input Validation
33
Low Risk
kill uses a hyphen prefixed numeric argument such as -62342 as a target process ID instead of a signal specification. GNU kill rejects this form, but uutils accepts it and sends a signal to the process with that PID. A script that forwards untrusted numbers into a kill invocation can terminate an unintended process. The fix validates hyphen prefixed numeric arguments so they are used as signal specifications rather than PIDs.
You are affected if you are using a version that falls within the vulnerable range and you pass untrusted numeric arguments to kill.
uu_kill is vulnerable to Improper Input Validation in versions 0.0.1 - 0.9.0.
Upgrade the uu_kill library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.