Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporaryMountDevice() function to temporarily mount a file system as root. An unprivileged user can prepare a symlink at this location to have the file system mounted in an arbitrary location. By winning a race condition, the attacker can also enter the mount point, thereby preventing a subsequent unmount of the file system.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
deepin-clone 后置链接漏洞
Vulnerability Description
deepin-clone是一款磁盘和分区备份/恢复工具。 deepin-clone 1.1.3之前版本中存在安全漏洞。攻击者可利用该漏洞进入挂载点,阻止文件系统的卸载。
CVSS Information
N/A
Vulnerability Type
N/A