Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable temporary "gunzip" program before executing it, which could allow local users to execute arbitrary commands by modifying the program before it is executed.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Tarantella Enterprise 3 gunzip竞争条件漏洞
Vulnerability Description
Tarantella Enterprise 3是一个基于Web的集中化的IT应用环境控制软件。 Tarantella Enterprise在安装过程中存在竞争条件问题,可以使本地攻击者得到主机的root权限。 在安装过程中,程序会在$TMPDIR环境变量指定的临时文件目录(通常是/tmp)中创建一个二进制的gunzip文件,此文件的文件名一般是gunzip$$,$$代表了进程号,安装程序会以root身份在以后的安装过程中用到这个gunzip程序。这个gunzip程序在被创建时是全局可读写的,如果能在它被使
CVSS Information
N/A
Vulnerability Type
N/A