LiME 1.12.0 及更早版本未能对磁盘采集的输出路径进行充分校验,且在打开操作员提供的路径参数时未使用 标志。这使得非特权本地用户能够覆盖任意由 root 用户拥有的文件。 如果攻击者能够控制输出目录,他们可以创建一个符号链接,该链接使用预期的文件名,并指向任意 root 拥有的文件。当采集过程在内核上下文中运行时,LiME 会跟随该符号链接,从而用内存采集数据流截断(truncates)目标文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet