CNCVE编号:CNCVE-20001103 CVE编号:CAN-2000-1103 安全级别:高 漏洞中文描述: BSD 3.0和4.0中的rcvtty不能正确的在执行一个脚本之前撤消权限,这允许本地攻击者通过在命令行中指定一个备用的特洛伊木马程序来获得权限。 漏洞英文描述: rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line. 漏洞参考: BUGTRAQ:20001127 BSDi 3.0/4.0 rcvtty gid=tty exploit... (mh package) | URL:http://www.securityfocus.com/archive/1/147120 | BID:2009 | URL:http://www.securityfocus.com/bid/2009 系统类型:其他 漏洞类型:输入有效性检查错误