Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file descriptor for those devices can be maintained after the user logs out, which allows that user to sniff activity on these devices when subsequent users log in.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
多个Linux厂商的pam_console漏洞
Vulnerability Description
Linux系统下的pam_console PAM模块有根据登陆用户修改多个设备文件属主的作用,但在用户退出登陆后,打开文件描述符仍将维护这些设备,随后的用户可以利用这个漏洞在登陆时做嗅探行为。
CVSS Information
N/A
Vulnerability Type
N/A