CNCVE编号:CNCVE-20010370 CVE编号:CAN-2001-0370 安全级别:中 漏洞中文描述: fcheck 2.57.59早期版本不安全地调用文件签名检查程序,这允许本地用户通过一个包括shell元字符的文件名来运行任意命令。 漏洞英文描述: fcheck prior to 2.57.59 calls the file signature checking program insecurely, which can allow a local user to run arbitrary commands via a file name that contains shell metacharacters. 漏洞参考: Reference: BUGTRAQ:20010320 fcheck prior to 2.07.59 - vulnerability - improper use of perl 'magic open' Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98521301510554&w=2 Reference: XF:fcheck-open-execute-commands Reference: URL:http://xfo 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:输入有效性检查错误