Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Automatic Bug Reporting Tool 权限许可和访问控制漏洞
Vulnerability Description
Automatic Bug Reporting Tool(ABRT)2.0.8版本和早期版本中的C处理程序插件中存在漏洞,该漏洞源于sysctl fs.suid_dumpable操作设置为2时未正确设置组(GID)在核心文件的setuid程序中的权限。本地攻击者可利用该漏洞获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A