Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering an execmod SELinux denial with a crafted binary filename, related to the commands.getstatusoutput function.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
setroubleshoot allow_execmod插件安全漏洞
Vulnerability Description
setroubleshoot是一套用于SELinux操作系统中的故障排除工具。该工具由框架和分析插件组成。allow_execmod是其中的一个任务文件检查插件。 setroubleshoot 3.2.23之前的版本中的allow_execmod插件中存在安全漏洞。本地攻击者可借助特制的二进制文件名利用该漏洞执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A