Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
Vulnerability Description
proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink entries whose linkname referenced another installed container and did not verify that the hardlink source container matched the destination container being restored, allowing a crafted restore archive to copy files between otherwise isolated containers. This issue is fixed in version 5.1.6.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Vulnerability Type
将资源暴露给错误范围
Vulnerability Title
Termux PRoot-Distro 权限许可和访问控制问题漏洞
Vulnerability Description
Termux PRoot-Distro是Termux组织开源的一个管理 Linux 发行版的虚拟化工具。 Termux PRoot-Distro 5.1.6之前版本存在权限许可和访问控制问题漏洞,该漏洞源于恢复过程中接受硬链接条目但未验证源容器与目标容器匹配,导致攻击者可通过特制的恢复归档文件在隔离容器间复制文件。
CVSS Information
N/A
Vulnerability Type
N/A