CNCVE编号:CNCVE-20010249 CVE编号:CAN-2001-0249 安全级别:高 漏洞中文描述: Solaris 8里FTP的后台程序的泄漏溢出问题,允许远程攻击者通过创建一个长的路径名和调用list命令来执行任意命令,list目录使用glob来创建长字符串。 漏洞英文描述: Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings. 漏洞参考: NAI:20010409 Globbing Vulnerabilities in Multiple FTP Daemons URL: http://www.pgp.com/research/covert/advisories/048.asp CERT:CA-2001-07 URL: http://www.cert.org/advisories/CA-2001-07.html BID:2550 URL: http://www.securityfocus.com/bid/2550 系统类型:其他 漏洞类型:输入有效性检查错误