Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2005-4347

EPSS 0.95% · P76
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2005-4347

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The Linux 2.4 kernel patch in kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux does not correctly set the "chroot barrier" with util-vserver, which allows attackers to access files on the host system that are outside of the vserver.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux VServer Project可突破CHROOT环境漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux-VServer是一个允许用户在一个普通的Linux服务器上建立虚拟专用的服务器的软件。 Linux-VServer存在典型的"chroot-again"问题,本地攻击者可以利用这个漏洞以ROOT用户权限在系统上执行任意指令。 主要问题是VServer应用程序针对"chroot-again"类型的攻击没有很好的进行安全保护,攻击者可以利用这个漏洞脱离限制环境,访问限制目录之外的任意文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2005-4347

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2005-4347

登录查看更多情报信息。

Same Patch Batch · n/a · 2006-03-22 · 19 CVEs total

CVE-2006-1344Verisign MPKI 6.0 Haydn.EXE跨站脚本攻击漏洞
CVE-2006-1352BEA WebLogic Server远程拒绝服务漏洞
CVE-2006-1351BEA WebLogic Server远程文件系统访问漏洞
CVE-2006-1350Free文章目录页面参数目录远程文件包含漏洞
CVE-2006-1349MusicBox多个输入验证漏洞
CVE-2006-1348gCards跨站脚本攻击漏洞
CVE-2006-1347gCards ‘loginfunction.php’SQL注入漏洞
CVE-2006-1346gCards多个目录遍历漏洞
CVE-2006-1345MyBB 'polls.php'"option[]=null" 参数敏感信息泄露漏洞
CVE-2006-0038Linux kernel 数字错误漏洞
CVE-2006-1358BEA WebLogic Portal JSR-168 Portlet信息泄露漏洞
CVE-2006-1357F5 Firepass 4100 SSL VPN跨站脚本攻击漏洞
CVE-2006-1356LibVC VCard 处理缓冲区溢出漏洞
CVE-2006-1355Avast! Antivirus本地不安全许可漏洞
CVE-2006-1354FreeRADIUS EAP-MSCHAPv2认证绕过漏洞
CVE-2006-1353ASP Portal多个SQL注入漏洞
CVE-2005-4418Util-VServer未知Linux功能漏洞
CVE-2006-0058Sendmail异步信号处理竞争条件漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2005-4347

No comments yet


Leave a comment