Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Format string vulnerability in the log function in SUS 2.0.2, and other versions before 2.0.6, allows local users to execute arbitrary code via format string specifiers in a command line argument that is passed directly to syslog.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SUS本地格式串处理漏洞
Vulnerability Description
SUS是一个suid root程序,允许普通用户使用超级用户权限执行部分程序。 SUS 2.0.2版本和2.0.6之前的其他版本的log()函数存在格式串问题,本地攻击者可以利用这个漏洞以root用户权限执行任意指令。
CVSS Information
N/A
Vulnerability Type
N/A