积极预防 及时发现
快速响应 力保恢复
ghostscript 5.10-16早期版本使用空的LD_RUN_PATH环境变量在当前目录下寻找...
发布时间:2001-01-09 信息来源:管理员

CNCVE编号:CNCVE-20001163 CVE编号:CVE-2000-1163 安全级别:中 漏洞中文描述: ghostscript 5.10-16早期版本使用空的LD_RUN_PATH环境变量在当前目录下寻找库文件,这允许本地用户通过在另一个用户所有的目录下放置特洛伊木马库,从而作为另一个用户来执行命令。 漏洞英文描述: ghostscript before 5.10-16 uses an empty LD_RUN_PATH environmental variable to find libraries in the current directory, which could allow local users to execute commands as other users by placing a Trojan horse library into a directory from which another user owned. 漏洞参考: CALDERA:CSSA-2000-041 | URL:http://www.calderasystems.com/support/security/advisories/CSSA-2000-041.0.txt | MANDRAKE:MDKSA-2000:074 | URL:http://www.linux-mandrake.com/en/security/MDKSA-2000-074.php3 | CONECTIVA:CLSA-2000:343 | URL:htt 系统类型:其他 漏洞类型:设计错误