CNCVE编号:CNCVE-20000947 CVE编号:CVE-2000-0947 安全级别:高 漏洞中文描述: 在 GNU CFEngine 1.6.0a11以前版本中cfd后台程序中的格式化字符串漏洞导致攻击者可以通过格式化CAUTH命令中的格式化字符串来执行任意命令。 漏洞英文描述: Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command. 漏洞参考: BUGTRAQ:20001002 Very probable remote root vulnerability in cfengine | URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0004.html | MANDRAKE:MDKSA-2000:061 | URL:http://www.linux-mandrake.com/en/security/MDKSA-2000-061.php3?dis=7.1 系统类型:其他 漏洞类型:输入有效性检查错误