Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Untrusted search path vulnerability in opcontrol in OProfile 0.9.1 and earlier allows local users to execute arbitrary commands via a modified PATH that references malicious (1) which or (2) dirname programs. NOTE: while opcontrol normally is not run setuid, a common configuration suggests accessing opcontrol using sudo. In such a context, this is a vulnerability.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OProfile OPControl路径规格本地提权漏洞
Vulnerability Description
OProfile 0.9.1及之前版本的opcontrol中存在不信任的搜索路径漏洞。本地用户可以借助经过修改的路径(引用(1) which或(2) dirname恶意程序)执行任意命令。注意:由于opcontrol通常不以setuid权限运行,通用配置建议使用sudo权限访问opcontrol。在这种上下文中,这是一个漏洞。
CVSS Information
N/A
Vulnerability Type
N/A