Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
MIMEDefang 2.80 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by the init-script.in and mimedefang-init.in scripts.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MIMEDefang 安全漏洞
Vulnerability Description
MIMEDefang是一款高性能的邮件过滤系统。 MIMEDefang 2.80及之前的版本中存在安全漏洞,该漏洞源于程序在移除账户权限后,创建了PID文件。本地攻击者可利用该漏洞终止任意进程。
CVSS Information
N/A
Vulnerability Type
N/A