积极预防 及时发现
快速响应 力保恢复
在各种Unix系统中的tcsh、csh、sh和bash当处理<<重定向(就是here-documen...
发布时间:2001-01-09 信息来源:管理员

CNCVE编号:CNCVE-20001134 CVE编号:CAN-2000-1134 安全级别:高 漏洞中文描述: 在各种Unix系统中的tcsh、csh、sh和bash当处理<<重定向(就是here-documents和in-heredocuments)时跟随符号连接,这允许本地用户通过符号连接攻击来覆盖其他用户的文件。 漏洞英文描述: tcsh, csh, sh, and bash on various Unix systems follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack. 漏洞参考: BUGTRAQ:20001028 tcsh: unsafe tempfile in << redirects | URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0418.html | BUGTRAQ:20001130 : RH6.x root from bash /tmp vuln + MORE | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=9 系统类型:其他 漏洞类型:权限有效性检查错误