Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command (within Bash) by a different user, as demonstrated by logging in as root and entering umount followed by a tab character for autocompletion.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
util-linux 权限许可和访问控制问题漏洞
Vulnerability Description
util-linux是一套用在Linux系统中并包含了多种系统管理工具的软件包,它提供加载、卸载、格式化、分区和管理硬盘驱动器,打开tty端口并得到内核消息等工具。 util-linux 2.32-rc1之前版本中的bash-completion/umount存在安全漏洞。本地攻击者可通过在mountpoint名称中注入shell命令利用该漏洞获取权限。
CVSS Information
N/A
Vulnerability Type
N/A