Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers to write to arbitrary files to the root directory via a / (slash) in a crafted archive, as demonstrated using the ar program.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GNU BinUtils elfutils 目录遍历漏洞
Vulnerability Description
GNU Binutils(又名GNU Binary Utilities或binutils)是GNU计划开发的一组编程语言工具程序,它主要用于处理多种格式的目标文件,并提供有连接器、汇编器和其他用于目标文件和档案的工具。elfutils通过提供一些工具及函数库用于替代GNU BinUtils。 elfutils 0.152和0.161版本的libelf/elf_begin.c文件中的‘read_long_names’函数存在目录遍历漏洞。远程攻击者可借助特制的‘/’利用该漏洞向root目录写入任意文件。
CVSS Information
N/A
Vulnerability Type
N/A