Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default configuration in OpenAFS 1.4.x before 1.4.4 and 1.5.x before 1.5.17 supports setuid programs within the local cell, which might allow attackers to gain privileges by spoofing a response to an AFS cache manager FetchStatus request, and setting setuid and root ownership for files in the cache.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenAFS FetchStatus 响应 特权提升漏洞
Vulnerability Description
OpenAFS 11.4.4之前的1.4.x版本和1.5.17之前的1.5.x版本中的默认配置支持本地cell内的setuid程序,这使得攻击者可以通过哄骗对AFS cache manager FetchStatus请求的响应和为cache中的文件设置setuid和root所有权,来获得特权。
CVSS Information
N/A
Vulnerability Type
N/A