漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`
Vulnerability Description
Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by replacing /etc/pihole/logrotate. The replacement is laundered to root:root ownership by pihole-FTL-prestart.sh and then parsed as root by the daily pihole flush cron, executing firstaction shell as uid 0. This issue is fixed in version 6.4.3.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
属主管理不恰当
Vulnerability Title
pi-hole 权限许可和访问控制问题漏洞
Vulnerability Description
Pi-hole是Pi-hole社区开源的一款网络级广告拦截应用程序。 Pi-hole 6.0.0版本至6.4.3之前版本存在权限许可和访问控制问题漏洞,该漏洞源于权限管理问题,可能导致具有代码执行权限的非特权用户通过替换/etc/pihole/logrotate文件实现权限提升至root。
CVSS Information
N/A
Vulnerability Type
N/A