Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Buffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long command line arguments.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Bonobo EFSTool命令行参数本地缓冲区溢出漏洞
Vulnerability Description
efstool是一款Linux操作系统下的EFS文件操作工具。 efstool对用户提交的命令行参数缺少正确的边界检查,本地攻击者可能利用这个漏洞进行缓冲区溢出攻击。 本地攻击者可以提交超长的字符串作为参数给efstool程序,可导致efstool产生段错误,由于efstool程序默认以suid root属性安装,精心构建字符串数据可使攻击者以root用户权限在系统中执行任意指令。
CVSS Information
N/A
Vulnerability Type
N/A