积极预防 及时发现
快速响应 力保恢复
FreeBSD 4.1.1的fingerd使远程攻击者可以通过指定目标文件的名字来代替正常的名字来阅...
发布时间:2000-12-19 信息来源:管理员

CNCVE编号:CNCVE-20000915 CVE编号:CVE-2000-0915 安全级别:中 漏洞中文描述: FreeBSD 4.1.1的fingerd使远程攻击者可以通过指定目标文件的名字来代替正常的名字来阅读任意文件。 漏洞英文描述: fingerd in FreeBSD 4.1.1 allows remote attackers to read arbitrary files by specifying the target file name instead of a regular user name. 漏洞参考: BUGTRAQ:20001002 | URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0017.html | FREEBSD:FreeBSD-SA-00:54 | URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories 系统类型:其他 漏洞类型:权限有效性检查错误