Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
GKSu 2.0.2, when sudo-mode is not enabled, uses " (double quote) characters in a gksu-run-helper argument, which allows attackers to execute arbitrary commands in certain situations involving an untrusted substring within this argument, as demonstrated by an untrusted filename encountered during installation of a VirtualBox extension pack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GKSu 权限许可和访问控制漏洞
Vulnerability Description
GKSu是一个对su和sudo提供GTK+前端的库,它主要用于当用户以root身份运行程序时提示输入密码。 GKSu 2.0.2版本中存在安全漏洞,该漏洞源于程序禁用sudo-mod后,‘gksu-run-helper’参数使用‘“’(双引号)字符。攻击者可利用该漏洞执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A