Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writable location. This allows standard users to deceive the package manager into using directories with pre-existing content, potentially leading to unauthorized actions or data manipulation. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
Vulnerability Type
缺省权限不正确
Vulnerability Title
Nix、lix和GNU Guix 安全漏洞
Vulnerability Description
GNU Guix是美国等都是美国(GNU)社区的产品。GNU Guix是一款开源的、跨平台程序包管理器。lix等都是(lix)开源的产品。lix是一款软件包管理器。Nix等都是(Nix)开源的产品。Nix是一个强大的包管理器。 Nix、lix和GNU Guix存在安全漏洞,该漏洞源于临时构建目录权限设置不当,可能导致未经授权的操作或数据操纵。以下产品及版本受到影响:Nix 2.24.15之前版本、2.26.4之前版本、2.28.4之前版本和2.29.1之前版本,Lix 2.91.2之前版本、2.92.2之
CVSS Information
N/A
Vulnerability Type
N/A