Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Red Hat PolicyKit pkexec命令安全漏洞
Vulnerability Description
Red Hat PolicyKit(又名Polkit)是美国红帽(Red Hat)公司的一个用于在Unix兼容系统中对应用程序进行权限控制的工具。该工具为现代桌面提供了一个中央框架用于授权一般应用程序进行特权工作。 Red Hat PolicyKit 0.113及之前版本的pkexec命令中存在安全漏洞。攻击者可利用该漏洞写入受限制终端,以用户权限执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A