Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The SUSE horde5 package before 5.0.2-2.4.1 sets incorrect ownership for certain configuration files and directories including /etc/apache2/vhosts.d, which allows local wwwrun users to gain privileges via unspecified vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Novell openSUSE 权限许可和访问控制漏洞
Vulnerability Description
Novell Novell openSUSE是美国Novell公司的一套基于Linux的自由操作系统。SUSE horde5是一套模块化的Web应用开发框架。 openSUSE 12.3版本的SUSE horde5-5.0.2-2.4.1之前的版本中存在安全漏洞,该漏洞源于程序对配置文件和包含/etc/apache2/vhosts.d在内的目录设置错误的所有权。本地具有‘wwwrun’权限的用户可利用该漏洞提升到root权限。
CVSS Information
N/A
Vulnerability Type
N/A