CNCVE编号:CNCVE-20000972 CVE编号:CVE-2000-0972 安全级别:低 漏洞中文描述: HP-UX 11.00 crontab允许本地用户在crontab会话过程中创建一个目标文件的symlink然后退出这个会话使用-e参数阅读crontab产生的错误信息,这样可以阅读任意文件。 漏洞英文描述: HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates. 漏洞参考: BUGTRAQ:20001020 < Hackerslab bug_paper > HP-UX crontab temporary file symbolic link vulnerability | URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0317.html | XF:hp-crontab-read-files | URL:http://xforce.iss.net/static/5410.php 系统类型:其他 漏洞类型:异常处理错误