漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by creating an executable file in a setgid directory through the (1) truncate or (2) ftruncate function in conjunction with memory-mapped I/O.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux kernel fs/open.c权限提升和信息泄露漏洞
Vulnerability Description
Linux Kernel是开放源代码操作系统Linux的内核。 Linux kernel 2.6.22之前版本的fs/open.c不会合理地消除setuid和setgid字节,当在写入文件时, 会允许本地用户获得不同组的特权,并通过在一个setgid目录中创建一个可执行文件至(1) truncate 或 (2) ftruncate 函数以及memory-mapped I/O中 ,来获得敏感信息或可能具有其他未知影响。
CVSS Information
N/A
Vulnerability Type
N/A