Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
IPCop (aka IPCop Firewall) before 1.4.10 has world-readable permissions for the backup.key file, which might allow local users to overwrite system configuration files and gain privileges by creating a malicious encrypted backup archive owned by "nobody", then executing ipcoprscfg to restore from this backup.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IPCop备份关键信息泄露漏洞
Vulnerability Description
IPCop (aka IPCop Firewall)的1.4.10之前版本的backup.key文件具有全域可读许可,本地用户可以通过创建所有人为"nobody"的恶意加密备份库,然后再执行icoprscfg从此备份中恢复,来重写系统配置文件并获取权限。
CVSS Information
N/A
Vulnerability Type
N/A