Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Second-order symlink vulnerability in eix-sync.in in Ebuild IndeX (eix) before 0.5.0_pre2 allows local users to overwrite arbitrary files via a symlink attack on the exi.X.sync temporary file, which is processed by the diff-eix program.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
EIX不安全的临时文件创建漏洞
Vulnerability Description
eix (Ebuild IndeX) 是用于Gentoo Linux portage系统上的搜索ebuilds的组件。 Ebuild IndeX (eix) 0.5.0_pre2之前版本的eix-sync.in中的第二顺序符号链接漏洞,可让本地用户通过符号链接攻击exi.X.sync临时文件来覆盖任意文件,这是由diff-eix程序处理的。
CVSS Information
N/A
Vulnerability Type
N/A