Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
conda-forge openssl-feedstock writable OPENSSLDIR
Vulnerability Description
conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR file path that can be written to by non-privilged local users. By writing a specially crafted openssl.cnf file in OPENSSLDIR, a non-privileged local user can execute arbitrary code with the privileges of the user or process loading openssl-feedstock DLLs. Miniforge before 24.5.0 is also affected.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
对搜索路径元素未加控制
Vulnerability Title
openssl-feedstock 安全漏洞
Vulnerability Description
openssl-feedstock是conda-forge开源的一个用于openssl的conda smithy存储库。 openssl-feedstock 066e83c之前版本存在安全漏洞,该漏洞源于OPENSSLDIR文件路径配置不当,可能导致执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A