Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit
Vulnerability Description
Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via crafted shell content placed at a predictable path in a world-writable temporary directory, which the installation step reads after elevating its own privileges.
To remediate this issue, users should upgrade to version 2.3.4.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
在具有不安全权限的目录中创建临时文件
Vulnerability Title
Amazon AWS F2 权限许可和访问控制问题漏洞
Vulnerability Description
Amazon AWS F2是美国Amazon公司的一个FPGA硬件加速开发框架。 Amazon AWS F2 2.3.4之前版本存在权限许可和访问控制问题漏洞,该漏洞源于FPGA管理工具安装组件在权限不安全的目录中创建临时文件,本地用户可在可预测路径的全局可写临时目录中放置特制Shell内容,安装步骤在提升自身权限后读取该内容,导致以root权限执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A