Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Insecure temporary file handling
Vulnerability Description
pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attacker can use this flaw to overwrite arbitrary files via symlinks.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
pyro 安全漏洞
Vulnerability Description
pyro是一套使用Python语言编写的分布式对象技术系统。 pyro 3.15之前版本中存在安全漏洞,该漏洞源于程序没有安全地处理临时目录中的pid文件并以root用户身份打开pid文件。攻击者可借助符号链接利用该漏洞覆盖任意文件。
CVSS Information
N/A
Vulnerability Type
N/A