漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Cpio: extraction allows symlinks which enables remote command execution
Vulnerability Description
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which allows files to be written in arbitrary directories through symlinks.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Vulnerability Title
cpio 后置链接漏洞
Vulnerability Description
cpio是一款用于类UNIX系统的文件备份程序。 CPIO存在后置链接漏洞,该漏洞源于存在路径遍历,允许未经身份验证的远程攻击者诱骗用户打开特制的存档,然后在目标系统上运行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A