¡¾Îó²îͨ¸æ¡¿glibc¾²Ì¬setuid³ÌÐòdlopen´úÂëÖ´ÐÐÎó²î (CVE-2025-4802)
Ðû²¼Ê±¼ä 2025-05-20Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | glibc¾²Ì¬setuid³ÌÐòdlopen´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-4802 | ||
Îó²îÀàÐÍ | ´úÂëÖ´ÐÐ | ·¢Ã÷ʱ¼ä | 2025-05-20 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
setuid¶þ½øÖÆÎļþÊǾßÓÐÌØÊâȨÏ޵ijÌÐò£¬£¬£¬£¬¿ÉÒÔÒÔÎļþÓµÓÐÕßµÄÉí·ÝÖ´ÐС£¡£¡£¡£dlopenÊÇÒ»¸ö¶¯Ì¬¼ÓÔØ¿âµÄº¯Êý£¬£¬£¬£¬Í¨³£ÓÃÓÚÔÚÔËÐÐʱ¼ÓÔØ¹²Ïí¿â¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ