Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The GridFTP in Globus Toolkit (GT) before 5.2.2, when certain autoconf macros are defined, does not properly check the return value from the getpwnam_r function, which might allow remote attackers to gain privileges by logging in with a user that does not exist, which causes GridFTP to run as the last user in the password file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Globus Toolkit ‘GridFTP’ 安全漏洞
Vulnerability Description
Globus Toolkit (GT) 5.2.2之前版本的GridFTP中存在漏洞,该漏洞源于当某些autoconf宏定义时未正确验证getpwnam_r函数的返回值。远程攻击者可通过不存在的用户登录(GridFTP作为密码文件中的最后用户运行),获取权限。
CVSS Information
N/A
Vulnerability Type
N/A