Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Openswan 2.2.x does not properly restrict permissions for (1) /var/run/starter.pid, related to starter.c in the IPsec starter, and (2) /var/lock/subsys/ipsec, which allows local users to kill arbitrary processes by writing a PID to a file, or possibly bypass disk quotas by writing arbitrary data to a file, as demonstrated by files with 0666 permissions, a different vulnerability than CVE-2011-1784.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Openswan安全绕过漏洞
Vulnerability Description
Xelerance Openswan是加拿大Xelerance公司的一个基于FreeS/WAN项目的用于Linux系统下的IPSEC实现,它主要用于保证数据传输中的安全性、完整性等问题。 Openswan 2.2.x版本不能正确限制/var/run/starter.pid(与IPsec starter中的starter.c有关)和/var/lock/subsys/ipsec的权限。本地用户可以通过向文件写入PID,终止任意进程,或者通过向文件写入任意数据,绕过磁盘分配。
CVSS Information
N/A
Vulnerability Type
N/A