Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control over DNS name resolution by opening a number of file descriptors before executing kppp.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
KPPP特权文件描述符泄漏漏洞
Vulnerability Description
KPPP是pppd的拨号程序和前端,允许交互脚本生成和网络设置。 KPPP的实现在权限处理上存在漏洞,本地攻击者可能利用些漏洞获取本地管理员权限。
CVSS Information
N/A
Vulnerability Type
N/A