Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks against unsafe usage of the chown and chmod programs.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
cron package 安全漏洞
Vulnerability Description
Debian是Debian Project合作组织创建的以Linux或FreeBSD为内核的自由操作系统。ubuntu是一个开源GNU/Linux操作系统。cron package是其中的一个调度守护进程安装包。 基于Debian平台的cron package 3.0pl1-128及之前的版本和基于Ubuntu平台的cron package 3.0pl1-128ubuntu2及之前的版本中存在安全漏洞。攻击者可通过实施符号链接攻击利用该漏洞将group crontab提升至root权限。
CVSS Information
N/A
Vulnerability Type
N/A