Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This could allow an attacker to gain access to privileged files and directories via a path traversal attack.
CVSS Information
N/A
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
pesign 路径遍历漏洞
Vulnerability Description
pesign是PE-COFF 二进制文件的签名工具,希望至少模糊地符合PE和Authenticode 规范。 pesign 存在安全漏洞。攻击者利用该漏洞通过路径遍历攻击访问特权文件和目录。
CVSS Information
N/A
Vulnerability Type
N/A