Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "authentication secrets."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Luci 竞争条件漏洞
Vulnerability Description
Luci是一套基于Lua脚本语言的MVC框架,它的目的是为OpenWrt固件(一个嵌入式的Linux发行版)能够从Whiterussian到Kamikaze实现快速配置接口。 Luci 0.26.0版本中存在竞争条件漏洞,该漏洞源于程序以全局可读权限创建/var/lib/luci/etc/luci.ini配置文件。本地攻击者可利用该漏洞读取文件并获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A