Astaro Security Linux Insecure File...

- AV AC AU C I A
发布: 2002-02-12
修订: 2025-04-13

Astaro Security Linux is an open source firewall implementation. It is developed and maintained by Astaro. Astaro Security Linux uses an insecure set of file and directory permissions. In a default implementation, sensitive system files are writeable by local users. While Astaro Security Linux is designed as a firewall implementation, and not a multi-user system, the design could allow an unprivileged user that has gained access to the system to take advantage of these file and directory permissions to perform nefarious activities. This problem makes it possible for an unprivileged user with access to the system via a shell to obscure their activity, perform an SSH man-in-the-middle attack, alter rpm checksums and potentially exploit the system with a trojaned rpm file, or other malicious activity.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息