Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default configuration of su in /etc/pam.d/su in GNU coreutils 5.2.1 allows local users to gain the privileges of a (1) locked or (2) expired account by entering the account name on the command line, related to improper use of the pam_succeed_if.so module.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GNU Coreutils pam_succeed_if PAM模块本地绕过认证漏洞
Vulnerability Description
GNU核心工具(Coreutils)是GNU操作系统所使用的基本文件、shell和文本操控工具。 Coreutils软件包没有对su命令正确地使用配置文件中的pam_succeed_if可插拔认证模块(PAM),如果运行su的用户知道目标帐号的口令的话,任何本地用户都可以使用这个命令更改锁定的或过期的用户帐号。
CVSS Information
N/A
Vulnerability Type
N/A