Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SCO UnixWare 7.1.1, 7.1.3, and Open UNIX 8.0.0 allows local users to bypass protections for the "as" address space file for a process ID (PID) by obtaining a procfs file descriptor for the file and calling execve() on a setuid or setgid program, which leaves the descriptor open to the user.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SCO UnixWare/Open UNIX不安全ProcFS处理漏洞
Vulnerability Description
UnixWare和Open Unix是由SCO公司开发和维护的商业性质Unix操作系统。 UnixWare和Open Unix的不安全处理procfs描述符,本地攻击者可以利用这个漏洞进行权限提升。 "/proc/$PID/as"包含进程$PID的地址空间映射,可以被其他文件打开和访问,并用于操作进程。进程属主也拥有文件权限为600的"as"文件。 但SCO UnixWare/Open UNIX的procfs实现存在漏洞允许本地攻击者绕过procfs setuid/setgid 'as'文件保护过程。这个
CVSS Information
N/A
Vulnerability Type
N/A