脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
脆弱性説明
proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain tarball root filesystems through _extract_plain_tar() in proot_distro/commands/install.py and Docker layers through _apply_layer() in proot_distro/helpers/docker.py without validating archive-controlled symlink targets in member.linkname, allowing a malicious archive to plant an absolute host-path symlink and write files through it onto the host filesystem. This issue is fixed in version 5.1.5.
CVSS情報
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
脆弱性タイプ
CWE-61
脆弱性タイトル
Termux PRoot-Distro 后置链接漏洞
脆弱性説明
Termux PRoot-Distro是Termux组织开源的一个管理 Linux 发行版的虚拟化工具。 Termux PRoot-Distro 5.1.5之前版本存在后置链接漏洞,该漏洞源于在提取tar包时未验证归档控制的符号链接目标,允许恶意归档在主机文件系统上创建绝对路径符号链接并写入文件。
CVSS情報
N/A
脆弱性タイプ
N/A