在 0.10.0 之前的 uutils coreutils 版本中,在确定所有权变更之前,会先对安装目标应用 setuid 或 setgid 权限位。这允许特权用户在所有权变更失败时,留下由该特权调用者拥有的 setuid 可执行文件。在具备能力限制(capability-restricted)的系统上,当所有权变更操作失败时,攻击者可以执行这些残留的 setuid 文件,从而获得提升的权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet