漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Abrt: chownproblemdir succeeds during active post-create event processing due to inadequate locking
Vulnerability Description
A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump directory with DD_OPEN_READONLY and calls dd_chown to change ownership of all files to the caller's uid, succeeding even while post-create event handlers hold a write lock. This allows an attacker to gain filesystem-level control of the dump directory while privileged event scripts are still running.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
使用共享资源的并发执行不恰当同步问题(竞争条件)
Vulnerability Title
abrt project ABRT 竞争条件问题漏洞
Vulnerability Description
abrt project abrt是abrt project团队开源的一套自动化故障报告工具。 abrt project ABRT存在竞争条件问题漏洞,该漏洞源于abrt - dbus D - Bus 服务的 ChownProblemDir 方法,ChownProblemDir 以 DD_OPEN_READONLY 打开转储目录,并调用 dd_chown 将所有文件的所有权更改为调用者的 uid,即便 post - create 事件处理程序持有写锁时此操作也能成功,导致攻击者可在特权事件脚本仍在运行时获
CVSS Information
N/A
Vulnerability Type
N/A