Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sysstat/lsag以不安全方式创建临时文件漏洞
Vulnerability Description
Sysstat是一款基于Linux平台的用于收集系统信息的统计程序。 Sysstat以不安全创建临时文件,本地攻击者可以利用这个漏洞利用符号连接破坏系统文件或造成权限提升。 本地攻击者可以在/tmp目录下精心构建符号链接覆盖系统文件,造成本地拒绝服务或权限提升。 其中Sysstat包含的lsag工具用于图形化显示这些统计,也存在同样问题。
CVSS Information
N/A
Vulnerability Type
N/A