Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
sng_regress in SNG 1.0.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/recompiled$$.png, (2) /tmp/decompiled$$.sng, and (3) /tmp/canonicalized$$.sng temporary files.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Eric_Raymond SNG 不安全临时文件创建漏洞
Vulnerability Description
SNG是一种表达可编辑,全文本的形式的PNG(便携式网络图形)的内容专门的标记语言。该项目支持SNG的编译器和PNG两者之间转换。 SNG 1.0.2版本的sng_regress允许本地用户可以借助在(1)/tmp/recompiled$$.png,(2)/tmp/decompiled$$.sng,和(3)/tmp/canonicalized$$.sng临时文件上的一个symlink攻击,重写任意文件。
CVSS Information
N/A
Vulnerability Type
N/A