Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The server daemons in Kannel 1.5.0 and earlier create a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by bearerbox.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Kannel 安全漏洞
Vulnerability Description
Kannel是Kannel团队的一款开源的WAP和SMS网关。 Kannel 1.5.0及之前的版本中存在安全漏洞,该漏洞源于程序在将账户降级为非root账户后,创建了PID文件。本地攻击者可利用该漏洞终止任意进程。
CVSS Information
N/A
Vulnerability Type
N/A