积极预防 及时发现
快速响应 力保恢复
KDE2(KDE 在2.2.0-6)中的kdesu程序不能正确的认证一个UNIX套接字的物主,而这个...
发布时间:2001-03-26 信息来源:管理员

CNCVE编号:CNCVE-20010178 CVE编号:CVE-2001-0178 安全级别:中 漏洞中文描述: KDE2(KDE 在2.2.0-6)中的kdesu程序不能正确的认证一个UNIX套接字的物主,而这个套接字是用来发送口令的,这允许本地用户偷到口令并获得权限。 漏洞英文描述: kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges. 漏洞参考: MANDRAKE:MDKSA-2001:018 CALDERA:CSSA-2001-005.0 SUSE:SuSE-SA:2001:02 XF:kde2-kdesu-retrieve-passwords 系统类型:其他 漏洞类型:权限有效性检查错误