积极预防 及时发现
快速响应 力保恢复
Midnight Commander 4.5.41及其早期版本中的cons.saver当输出文件描述...
发布时间:2001-01-09 信息来源:管理员

CNCVE编号:CNCVE-20001108 CVE编号:CVE-2000-1108 安全级别:中 漏洞中文描述: Midnight Commander 4.5.41及其早期版本中的cons.saver当输出文件描述符为TTY时不能正确的校验,这允许本地用户通过往目标文件创建符号链接、调用mc和指定作为TTY连接来破坏文件。 漏洞英文描述: cons.saver in Midnight Commander (mc) 4.5.42 and earlier does not properly verify if an output file descriptor is a TTY, which allows local users to corrupt files by creating a symbolic link to the target file, calling mc, and specifying that link as a TTY. 漏洞参考: BUGTRAQ:20001113 Problems with cons.saver | URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0192.html | DEBIAN:20001125 mc: local DoS | URL:http://www.debian.org/security/2000/20001125 | BID:1945 | URL:http://www.securityfoc 系统类型:其他 漏洞类型:设计错误