积极预防 及时发现
快速响应 力保恢复
Joe 文本编辑器2.8为.joerc配置文件搜索现在工作的目录,这允许本地用户通过放置特洛伊木马....
发布时间:2001-05-03 信息来源:管理员

CNCVE编号:CNCVE-20010289 CVE编号:CVE-2001-0289 安全级别:中 漏洞中文描述: Joe 文本编辑器2.8为.joerc配置文件搜索现在工作的目录,这允许本地用户通过放置特洛伊木马.joerc文件到一个目录然后等待用户执行这个文件来获得其他用户的权限。 漏洞英文描述: Joe text editor 2.8 searches the current working directory (CWD) for the .joerc configuration file, which could allow local users to gain privileges of other users by placing a Trojan Horse .joerc file into a directory, then waiting for users to execute it. 漏洞参考: Reference: BUGTRAQ:20010228 Joe's Own Editor File Handling Error Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0490.html Reference: MANDRAKE:MDKSA-2001:026 Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001 系统类型:其他 漏洞类型:设计错误