Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple race conditions in Smb4K before 0.8.0 allow local users to (1) modify arbitrary files via unspecified manipulations of Smb4K's lock file, which is not properly handled by the remove_lock_file function in core/smb4kfileio.cpp, and (2) add lines to the sudoers file via a symlink attack on temporary files, which isn't properly handled by the writeFile function in core/smb4kfileio.cpp.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Smb4K 多个竞争条件漏洞
Vulnerability Description
Smb4K 0.8.0版本之前的版本中存在多个竞争状态。本地用户(1)可以借助魏明的对Smb4K的锁定文件操作来修改任意文件,且该锁定文件没有经过core/smb4kfileio.cpp的remove_lock_file函数的适当处理,同时,(2) add lines to the sudoers file可以借助临时文件上的一个symlink攻击,向sudoers文件添加行,且该文件没有经过core/smb4kfileio.cpp的writeFile函数的适当处理。
CVSS Information
N/A
Vulnerability Type
N/A