Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by precreating a temporary directory.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ubuntu bzip2本地权限提升漏洞
Vulnerability Description
bzip2是英国软件开发者Julian Seward所研发的一套用于类Unix操作系统中的开源文件压缩和解压工具。 bzip2 1.0.4及之前版本的bzexe命令中存在安全漏洞,该漏洞源于当生成压缩的可执行文件提取时,程序没有正确处理临时文件。本地攻击者可通过创建临时目录利用该漏洞执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A