Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A race condition in nessus-adduser in Nessus 2.0.11 and possibly earlier versions, if the TMPDIR environment variable is not set, allows local users to gain privileges.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Nessus以不安全方式创建临时文件漏洞
Vulnerability Description
Nessus是一款流行的漏洞扫描程序。 Nessus的'nessus-adduser'以不安全方式创建临时文件,本地攻击者可以利用这个漏洞破坏系统文件。 'nessus-adduser'脚本用于增加Nessus用户,当建立用户时,Nessus以不安全方式创建临时文件,非特权用户可以通过符号链接,当管理员增加用户执行脚本时,导致目标文件破坏,可能存在提升权限问题。
CVSS Information
N/A
Vulnerability Type
N/A