积极预防 及时发现
快速响应 力保恢复
当在调试方式下运行时,ypbind 3.3的记录功能中的格式化字符串漏洞会泄漏文件描述符以及允许攻击...
发布时间:2000-12-11 信息来源:管理员

CNCVE编号:CNCVE-20001040 CVE编号:CVE-2000-1040 安全级别:高 漏洞中文描述: 当在调试方式下运行时,ypbind 3.3的记录功能中的格式化字符串漏洞会泄漏文件描述符以及允许攻击者引发拒绝服务。 漏洞英文描述: Format string vulnerability in logging function of ypbind 3.3, while running in debug mode, leaks file descriptors and allows an attacker to cause a denial of service. 漏洞参考: DEBIAN:20001014 nis: local exploit | URL:http://www.debian.org/security/2000/20001014 | MANDRAKE:MDKSA-2000:064 | URL:http://www.linux-mandrake.com/en/security/MDKSA-2000-064.php3?dis=7.1 | SUSE:SuSE-SA:2000:042 | URL:http://archives.n 系统类型:其他 漏洞类型:输入有效性检查错误