Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites
Vulnerability Description
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Vulnerability Title
Redhat libreport 后置链接漏洞
Vulnerability Description
Redhat libreport是美国Redhat公司开源的一个问题报告通用库。 Redhat libreport存在后置链接漏洞,该漏洞源于事件脚本使用 shell 重定向写入输出文件时未设置 O_NOFOLLOW 标志,若目标文件被替换为符号链接,以 root 身份运行的 shell 进程会跟随该符号链接并将内容写入符号链接指向的目标,导致系统上可发生任意文件覆盖。
CVSS Information
N/A
Vulnerability Type
N/A