漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
漏洞
N/A
漏洞信息
An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's kauth_ktexteditor_helper service (as utilized in the Kate text editor) can allow other unprivileged users on the local system to gain root privileges. The attack occurs when one user (who has an unprivileged account but is also able to authenticate as root) writes a text file using Kate into a directory owned by a another unprivileged user. The latter unprivileged user conducts a symlink attack to achieve privilege escalation.
漏洞信息
N/A
漏洞
N/A
漏洞
KTextEditor 安全漏洞
漏洞信息
KTextEditor是一款KDE Frameworks中的提供高级纯文本编辑功能的编辑器。 KTextEditor 5.34.0版本至5.45.0版本中存在安全漏洞,该漏洞源于KTextEditor的kauth_ktexteditor_helper服务没有正确的处理临时文件。攻击者可通过向其他非特权用户所有的目录写入文本文件并通过其他用户实施符号链接攻击利用该漏洞获取root权限。
漏洞信息
N/A
漏洞
N/A