Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ntfs-3g: Modprobe influence vulnerability via environment variables
Vulnerability Description
Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege escalation.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Tuxera NTFS-3G 权限许可和访问控制问题漏洞
Vulnerability Description
Tuxera NTFS-3G是芬兰Tuxera公司的一套开源的、跨平台的用于支持NTFS分区读写的驱动程序。 Tuxera NTFS-3G中存在本地提权漏洞,该漏洞源于程序在以提升的权限执行modprobe之前没有清理该环境。本地攻击者可利用该漏洞获取root权限。
CVSS Information
N/A
Vulnerability Type
N/A