积极预防 及时发现
快速响应 力保恢复
J-Pilot的安装创建了含有用户umask的.jpilot目录,要是其他用户的umask没有安全设...
发布时间:2001-02-12 信息来源:管理员

CNCVE编号:CNCVE-20010067 CVE编号:CAN-2001-0067 安全级别:中 漏洞中文描述: J-Pilot的安装创建了含有用户umask的.jpilot目录,要是其他用户的umask没有安全设定,就会允许本地攻击者能够阅读他们的PalmOS备份信息。 漏洞英文描述: The installation of J-Pilot creates the .jpilot directory with the user's umask, which could allow local attackers to read other users' PalmOS backup information if their umasks are not securely set. 漏洞参考: XF:jpilot-perms MANDRAKE:MDKSA-2000:081 BUGTRAQ:20001214 J-Pilot Permissions Vulnerability 系统类型:其他 漏洞类型:权限有效性检查错误