Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Vulnerability in FAM 2.6.8, 2.6.6, and other versions allows unprivileged users to obtain the names of files whose access is restricted to the root group.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SGI FAM可获取任意root属主目录文件列表漏洞
Vulnerability Description
fam是一款由SGI开发和维护的开放源代码文件更改监视工具,也可以使用在其他Linux和Unix操作系统下。 fam存在设计错误,本地攻击者可以利用这个漏洞获得高权限属主目录下的敏感文件名。 当执行FAM对某一个目录进行监视时,对于只属于组成员的用户来说,本应该只会返回Exists和EndExist事件,如: # ls -ld /root drwxr-x--- ... root root ... /root # fam % ./test -d /root FAMMonitorDirectory("/roo
CVSS Information
N/A
Vulnerability Type
N/A