Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earlier, generates an installer that allows local users to cause a denial of service via a symlink attack on the bitrock_installer.log temporary file. NOTE: it is possible that this vulnerability is present in other products that use this installer.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Process-one ejabberd bitrock_installer.log临时文件 拒绝服务漏洞
Vulnerability Description
包括Process-one ejabberd 1.1.1_1及之前版本在内的产品当中使用的第三方安装程序生成工具,可能是BitRock InstallBuilder,会生成一个安装程序,该安装程序可以使本地用户通过对bitrock_installer.log临时文件的符号链接攻击,引起拒绝服务。注意:使用该安装程序的其他产品中也可能存在此漏洞。
CVSS Information
N/A
Vulnerability Type
N/A