Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
include/tests_webservers in Lynis before 1.5.5 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/lynis.*.unsorted file with an easily determined name.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Lynis 安全漏洞
Vulnerability Description
Lynis是软件开发者Michael Boelen所研发的一套开源的系统安全审计工具。该工具由一系列的shell脚本构成,可检测系统中安装的程序包、配置上的错误、以及安全问题和系统信息等。 Lynis 1.5.5之前的版本中的include/tests_webservers存在安全漏洞。本地攻击者可通过对/tmp/lynis.*.unsorted文件实施符号链接攻击利用该漏洞覆盖任意文件。
CVSS Information
N/A
Vulnerability Type
N/A