CNCVE编号:CNCVE-20000312 CVE编号:CAN-2000-0312 安全级别:高 漏洞中文描述: OpenBSD 2.5的cron允许本地用户通过不以NULL结尾的argv<>来获得root权限,这个参数将传递给cron的fake popen函数。 漏洞英文描述: cron in OpenBSD 2.5 allows local users to gain root privileges via an argv<> that is not NULL terminated, which is passed to cron's fake popen function. 漏洞参考: OPENBSD:19990830 In cron(8), make sure argv<> is NULL terminated in the fake popen() and run sendmail as the user, not as root. 系统类型:其他 漏洞类型:其他