Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow local users to obtain sensitive information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux Kernel 信息泄露漏洞
Vulnerability Description
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。 Linux kernel 2.4.x版本、2.6.24-rc3及之前的2.6.x版本和其他版本中的fs/exec.c文件的do_coredump函数存在信息泄露漏洞,该漏洞源于程序在将core转储到已有文件时没有正确地验证core dump文件的用户ID。本地攻击者可利用该漏洞获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A