Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
scrollkeeper-get-cl in ScrollKeeper 0.3 to 0.3.11 allows local users to create and overwrite files via a symlink attack on the scrollkeeper-tempfile.x temporary files.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ScrollKeeper不安全临时文件名权限提升漏洞
Vulnerability Description
ScrollKeeper是一款管理文档数据的系统,可以用于把文档归类,跟踪档案是否可用,具体位置,提供各种语言、格式、主题、版本属性等功能。 ScrollKeeper在建立临时文件的时候不够安全,本地攻击者可以利用这个漏洞进行符号连接攻击。 ScrolKeeper系统包含名为Scrollkeeper-get-cl的程序,通过ScrollKeeper-aware browsers如Nautilus浏览器调用Scrollkeeper-get-cl程序可以获得文档类别树,其内容列表由保存在/tmp目录下的临时文
CVSS Information
N/A
Vulnerability Type
N/A