Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
suidperl (aka sperl) does not properly cleanse the escape sequence "~!" before calling /bin/mail to send an error report, which allows local users to gain privileges by setting the "interactive" environmental variable and calling suidperl with a filename that contains the escape sequence.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
suidperl(也称为sperl) /bin/mail权限提升漏洞
Vulnerability Description
suidperl(也称为sperl)在调用/bin/mail发送错误报告前不正确清除转义序列,本地用户可以利用该漏洞通过设置“interactive”环境变量,以及调用文件名包含转义序列的suidperl获取权限。
CVSS Information
N/A
Vulnerability Type
N/A