积极预防 及时发现
快速响应 力保恢复
KTH Kerberos IV 允许本地用户通过使用krb4_proxy变量来指定另一个代理,这允许...
发布时间:2001-02-16 信息来源:管理员

CNCVE编号:CNCVE-20010034 CVE编号:CVE-2001-0034 安全级别:高 漏洞中文描述: KTH Kerberos IV 允许本地用户通过使用krb4_proxy变量来指定另一个代理,这允许用户产生错误的代理响应并有可能获得权限。 漏洞英文描述: KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to generate false proxy responses and possibly gain privileges. 漏洞参考: XF:kerberos4-arbitrary-proxy BUGTRAQ:20001210 KTH upgrade and FIX BUGTRAQ:20001208 Vulnerabilities in KTH Kerberos IV 系统类型:其他 漏洞类型:权限有效性检查错误