Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
logcheck before 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary directory in /var/tmp.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Logcheck不安全临时目录漏洞
Vulnerability Description
logcheck是一款日志检测工具。 logcheck在利用临时目录时没有采取任何安全检查,本地攻击者可以利用这个漏洞以Root权限覆盖系统文件,造成拒绝服务。 当logcheck安装时,会建立/var/tmp临时目录,当这个目录存在时,没有任何漏洞,但是如果这个目录被删除,那么再次运行logcheck时,由于不正确检查临时目录,攻击者可以利用符号连接对系统进行攻击,以root用户权限覆盖系统文件。
CVSS Information
N/A
Vulnerability Type
N/A