CNCVE编号:CNCVE-20000918 CVE编号:CAN-2000-0918 安全级别:高 漏洞中文描述: KDE 1.1.2的kvt中的格式化字符串漏洞可能导致本地用户通过一个包括格式化字符的DISPLAY环境变量来执行任意命令。 另外:现在仍无此 bug的攻击程序可用. 漏洞英文描述: Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters. INCLUSION: It has not been proven that this bug is exploitable. 漏洞参考: BID:1700 | URL:http://www.securityfocus.com/bid/1700 | BUGTRAQ:20000919 kvt format bug | URL:http://www.securityfocus.com/archive/1/83914 系统类型:其他 漏洞类型:输入有效性检查错误