Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
gnc-test-env in GnuCash 2.3.15 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GnuCash LD_LIBRARY_PATH设计错误漏洞
Vulnerability Description
GnuCash 是一套提供复式簿记系统的会计软件。 GnuCash 2.3.15以及之前版本中的gnc-test-env在LD_LIBRARY_PATH中放置了零长度目录名称。本地用户可以借助在当前工作目录中共享库文件的Trojan木马获得权限提升。
CVSS Information
N/A
Vulnerability Type
N/A