Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbitrary code via the GSSAPI_MECH_CONF environment variable, as demonstrated using mount.nfs.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
libgssapi/libgssglue 'GSSAPI_MECH_CONF'环境变量本地权限提升漏洞
Vulnerability Description
libgssapi和libgssglue 0.4之前版本中存在权限提升漏洞。本地用户可借助GSSAPI_MECH_CONF环境变量获得特权。
CVSS Information
N/A
Vulnerability Type
N/A