Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Exposed Dangerous Method or Function
Vulnerability Description
The package guake before 3.8.5 are vulnerable to Exposed Dangerous Method or Function due to the exposure of execute_command and execute_command_by_uuid methods via the d-bus interface, which makes it possible for a malicious user to run an arbitrary command via the d-bus method. **Note:** Exploitation requires the user to have installed another malicious program that will be able to send dbus signals or run terminal commands.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L
Vulnerability Type
N/A
Vulnerability Title
guake 安全漏洞
Vulnerability Description
guake是一个为 GNOME 桌面环境设计的基于 python 的下拉终端。 guake 存在安全漏洞,该漏洞源于 guake 通过 d-bus 接口暴露了execute_command和execute_command_by_uuid方法,这使得恶意用户可以通过 d-bus 方法运行任意命令 。该漏洞影响以下产品:guake 3.8.5 之前版本。
CVSS Information
N/A
Vulnerability Type
N/A