FreeBSD Package Add Insecure...

- AV AC AU C I A
发布: 2002-01-04
修订: 2025-04-13

FreeBSD is a freely available, open source clone of the Unix Operating System. It is maintained by the FreeBSD project. When pkg_add is executed, the directory the contents of the package are extracted to is created with permissions of 755. With this permission set, it is possible for a local user to descend the directory tree. In the event that any subdirectories have been created with world-writable permissions, the user could either remove the data in those directories, or trojan the files to later gain elevated privileges.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息