积极预防 及时发现
快速响应 力保恢复
APC UPS daemon、apcupsd将其进程ID保存在一个全局可写的文件中,这允许本地用户通...
发布时间:2001-02-16 信息来源:管理员

CNCVE编号:CNCVE-20010040 CVE编号:CVE-2001-0040 安全级别:中 漏洞中文描述: APC UPS daemon、apcupsd将其进程ID保存在一个全局可写的文件中,这允许本地用户通过在apuscd.pid文件中指定目标进程的ID来中止任意的进程。 漏洞英文描述: APC UPS daemon, apcupsd, saves its process ID in a world-writeable file, which allows local users to kill an arbitrary process by specifying the target process ID in the apcupsd.pid file. 漏洞参考: BID:2070 XF:apc-apcupsd-dos MANDRAKE:MDKSA-2000:077 BUGTRAQ:20001206 apcupsd 3.7.2 Denial of Service 系统类型:其他 漏洞类型:配置错误