A vulnerability, which was classified as critical, was found in kylin-system-updater up to 1.4.20kord on Ubuntu Kylin. Affected is the function InstallSnap of the component Update Handler. The manipulation leads to command injection. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222600.
References
Link Resource
https://github.com/cn-lwj/vuldb/blob/master/kylin-system-updater_vuln.md Exploit Third Party Advisory
https://vuldb.com/?ctiid.222600 Permissions Required Third Party Advisory
https://vuldb.com/?id.222600 Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: VulDB

Published: 2023-03-08T18:06:40.265Z

Updated: 2024-02-13T07:52:53.508Z

Reserved: 2023-03-08T18:05:26.376Z


Link: CVE-2023-1277

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-03-08T19:15:10.760

Modified: 2024-05-17T02:17:56.127


Link: CVE-2023-1277

JSON object: View

cve-icon Redhat Information

No data.