CNCVE编号:CNCVE-20001109 CVE编号:CVE-2000-1109 安全级别:中 漏洞中文描述: Midnight Commander 4.5.51及其早期版本在用户打开目录时不能正确的处理变形的目录名,这允许其他本地用户用命令创建包含特殊字符的命令来获得权限。 漏洞英文描述: Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a directory, which allows other local users to gain privileges by creating directories that contain special characters followed by the command. 漏洞参考: BUGTRAQ:20001127 Midnight Commander | URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0373.html | BID:2016 | URL:http://www.securityfocus.com/bid/2016 系统类型:其他 漏洞类型:输入有效性检查错误