Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Solaris priocntl系统调用设计错误导致权限提升漏洞
Vulnerability Description
Solaris是一款由Sun Microsystems公司开发和维护的商业UNIX操作系统。 Solaris中的priocntl在调用参数时对用户的数据缺少正确过滤,本地攻击者可以利用这个漏洞无需ROOT权限指定加载任意内核模块,或在核心态下执行任意代码。 Solaris中的priocntl系统调用用于进程切换控制,其调用方法如下: long priocntl(idtype_t idtype, id_t id, int cmd, /* arg */ ...); 当'cmd'参数设置为PC_GETCID时,
CVSS Information
N/A
Vulnerability Type
N/A