漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys
Vulnerability Description
A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. This can occur either through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race. Successful exploitation allows the attacker to gain ownership of arbitrary root-owned files or directories, leading to root access. This vulnerability requires an external management layer (e.g., libvirt) to trigger the affected code path.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
CWE-61
Vulnerability Title
QEMU 后置链接漏洞
Vulnerability Description
qemu是QEMU组织开源的一款虚拟化模拟器。 QEMU存在后置链接漏洞,该漏洞源于guest-ssh-add-authorized-keys命令处理程序中的符号链接操纵问题,可能通过确定性的目录符号链接绕过或TOCTOU文件符号链接竞争条件被利用,导致本地非特权用户获取任意root拥有文件或目录的所有权,从而获得root访问权限。
CVSS Information
N/A
Vulnerability Type
N/A