su-exec 0.3 及更早版本在使用 解析数值型用户和组标识符时,未对其有效性进行充分校验。若输入的数值超出 和 的表示范围,溢出部分会被截断,导致值变为 0(即 root 的标识符)。攻击者可借此提供足够大的数值标识符,使其截断后等于 root 的 uid/gid(均为 0),从而使 su-exec 以 root 权限执行目标程序,而非预期的非特权账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet