Multiple Linux Vendor TCLTK Unsafe...

- AV AC AU C I A
发布: 2001-07-19
修订: 2025-04-13

TCL/TK is the Tool Command Language/Toolkit originally developed by Sun Microsystems, and now maintained by public domain. When executed on some Linux systems, TCL searches the current working directory for certain libraries. A local user may be able to place one of the searched libraries in a world-writable directory. Upon a user executing a program that uses TCL in the directory, the contents of the library would be loaded, and executed with the permissions of the user.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息