漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit
Vulnerability Description
Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via crafted shell content placed at a predictable path in a world-writable temporary directory, which the installation step reads after elevating its own privileges.
To remediate this issue, users should upgrade to version 2.3.4.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
在具有不安全权限的目录中创建临时文件
Vulnerability Title
Amazon AWS F2 权限许可和访问控制问题漏洞
Vulnerability Description
Amazon AWS F2是美国Amazon公司的一个FPGA硬件加速开发框架。 Amazon AWS F2 2.3.4之前版本存在权限许可和访问控制问题漏洞,该漏洞源于FPGA管理工具安装组件在权限不安全的目录中创建临时文件,本地用户可在可预测路径的全局可写临时目录中放置特制Shell内容,安装步骤在提升自身权限后读取该内容,导致以root权限执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A