Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary commands, a different vulnerability than CVE-1999-1332.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GNU gzexe临时文件命令执行漏洞
Vulnerability Description
GNU gzexe是一个压缩可执行文件的工具。 gzexe在建立临时文件时存在问题,本地攻击者可以利用这个漏洞以用户进程权限执行任意命令。 gzexe在建立临时文件时,如果建立文件设备,gzexe就会去执行参数程序,因此如果攻击者提供恶意参数,在某些情况下建立文件失败,就可能以用户进程权限执行恶意命令。
CVSS Information
N/A
Vulnerability Type
N/A