ACL ACL是ACL组织开源的一款用于实现访问控制与权限管理的安全权限控制框架。 acl 2.4.0之前版本存在竞争条件问题漏洞,该漏洞源于TOCTOU竞争条件问题,允许本地攻击者通过替换lstat()检查与后续符号链接跟踪操作之间的路径名组件为符号链接,从而在特权进程在攻击者控制的路径上调用getfacl、setfacl或chacl时重定向文件访问控制列表操作,导致本地权限提升。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| acl project | acl | < 2.4.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| acl project | acl | 0 ~ 2.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet