Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an unspecified IPC message queue, which allows local users to inject arbitrary messages by writing to that queue.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Xymon 安全漏洞
Vulnerability Description
Xymon是一套开源的、跨平台的网络监控应用程序。该应用程序可通过网页查看各服务器的运行状态,并支持Email及短信通知功能。 Xymon的lib/xymond_ipc.c文件中存在安全漏洞,该漏洞源于程序对IPC消息序列使用弱权限(666)。本地攻击者可通过写入该队列利用该漏洞插入任意消息。以下版本受到影响:Xymon 4.1.x版本,4.2.x版本,4.3.25之前4.3.x版本。
CVSS Information
N/A
Vulnerability Type
N/A