CNCVE编号:CNCVE-20000803 CVE编号:CVE-2000-0803 安全级别:中 漏洞中文描述: GNU Groff使用当前正在使用的目录来找寻设备描述文件,这将允许本地用户获得额外的权限,他们可以通过将恶意的postpro指令写入描述文件,其他用户运行groff的时候它们会自动执行。 漏洞英文描述: GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive in the description file, which is executed when another user runs groff. 漏洞参考: ISS:20001004 GNU Groff utilities read untrusted commands from current working directory 系统类型:其他 漏洞类型:其他