漏洞标题
N/A
漏洞描述信息
在Dmidecode 3.5之前,可以使用-dump-bin来覆盖本地文件。这具有安全 relevance,因为例如,通过sudo执行Dmidecode是可能的。
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. NOTE: Some third parties have indicated the fix in 3.5 does not adequately address the vulnerability. The argument is that the proposed patch prevents dmidecode from writing to an existing file. However, there are multiple attack vectors that would not require overwriting an existing file that would provide the same level of unauthorized privilege escalation (e.g. creating a new file in /etc/cron.hourly).
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
dmidecode 安全漏洞
漏洞描述信息
dmidecode是一种用于以人类可读的格式转储计算机的 DMI 表内容的工具。 dmidecode 3.5 之前版本存在安全漏洞,该漏洞源于允许通过dump-bin 覆盖本地文件。
CVSS信息
N/A
漏洞类别
其他