漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Abrt: unsanitized systemd journal content written to dump directory files enables content injection
Vulnerability Description
A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A local user can inject arbitrary content into the journal output by embedding newline characters in syslog messages, controlling the content that root writes to dump directory files.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
输出中的特殊元素转义处理不恰当(注入)
Vulnerability Title
Redhat libreport 输入验证错误漏洞
Vulnerability Description
Redhat libreport是美国Redhat公司开源的一个问题报告通用库。 Redhat libreport存在输入验证错误漏洞,该漏洞源于事件脚本查询 systemd 日志获取与崩溃进程匹配日志条目并写入 dump 目录文件时,未过滤嵌入控制字符,导致本地用户能通过在 syslog 消息嵌入换行符向日志输出注入任意内容,进而控制 root 写入 dump 目录文件的内容。
CVSS Information
N/A
Vulnerability Type
N/A