积极预防 及时发现
快速响应 力保恢复
在HP资源监视器服务中的注册管理程序允许本地用户通过从命名原来的registrar.log日志文件并...
发布时间:2001-01-09 信息来源:管理员

CNCVE编号:CNCVE-20001127 CVE编号:CAN-2000-1127 安全级别:中 漏洞中文描述: 在HP资源监视器服务中的注册管理程序允许本地用户通过从命名原来的registrar.log日志文件并创建对目标文件的符号链接来修改任意文件。 漏洞英文描述: registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the original registrar.log log file and creating a symbolic link to the target file, to which registrar appends log information and sets the per 漏洞参考: BUGTRAQ:20001108 HP-UX 10.20 resource monitor service | URL:http://www.securityfocus.com/archive/1/143845 | BID:1919 | URL:http://www.securityfocus.com/bid/1919 系统类型:其他 漏洞类型:权限有效性检查错误