积极预防 及时发现
快速响应 力保恢复
Debian 2.2中Proftpd的postinst在用户匿名访问时安装脚本不能正确的更改“run...
发布时间:2001-06-27 信息来源:管理员

CNCVE编号:CNCVE-20010456 CVE编号:CVE-2001-0456 安全级别:高 漏洞中文描述: Debian 2.2中Proftpd的postinst在用户匿名访问时安装脚本不能正确的更改“run as uid/gid root”配置,这使服务器以比预想的更高的权限来运行。 漏洞英文描述: postinst installation script for Proftpd in Debian 2.2 does not properly change the "run as uid/gid root" configuration when the user enables anonymous access, which causes the server to run at a higher privilege than intended. 漏洞参考: Reference: DEBIAN:DSA-032 Reference: URL:http://www.debian.org/security/2001/dsa-032 Reference: XF:proftpd-postinst-root Reference: URL:http://xforce.iss.net/static/6208.php 系统类型:其他 漏洞类型:配置错误