Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test.mmrow app for Ubuntu phone.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ubuntu click 安全漏洞
Vulnerability Description
Ubuntu是英国科能(Canonical)公司和Ubuntu基金会共同开发的一套以桌面应用为主的GNU/Linux操作系统。Ubuntu LTS是一个长期支持版本。click是其中的一个安装在文件系统内适用于第三方应用程序的简化打包格式文件。 Ubuntu 15.04版本和Ubuntu 14.04 LTS版本中的click的install.py文件存在安全漏洞。攻击者可借助含有特制路径文件的数据原始码利用该漏洞获取权限。
CVSS Information
N/A
Vulnerability Type
N/A