积极预防 及时发现
快速响应 力保恢复
KTH Kerberos IV允许本地用户通过指定使用KRBCONFDIR环境变量的另一个目录来以提...
发布时间:2001-02-16 信息来源:管理员

CNCVE编号:CNCVE-20010033 CVE编号:CVE-2001-0033 安全级别:高 漏洞中文描述: KTH Kerberos IV允许本地用户通过指定使用KRBCONFDIR环境变量的另一个目录来以提升的权限改变Kerberos服务器的配置,这允许用户获得额外的权限。 漏洞英文描述: KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows the user to gain additional privilege 漏洞参考: XF:kerberos4-user-config BUGTRAQ:20001210 KTH upgrade and FIX BUGTRAQ:20001208 Vulnerabilities in KTH Kerberos IV 系统类型:其他 漏洞类型:权限有效性检查错误