积极预防 及时发现
快速响应 力保恢复
Samba2.2.0以前的版本允许本地攻击者通过使用针对打印机查询队列、smbclient的more...
发布时间:2001-07-02 信息来源:管理员

CNCVE编号:CNCVE-20010406 CVE编号:CAN-2001-0406 安全级别:中 漏洞中文描述: Samba2.2.0以前的版本允许本地攻击者通过使用针对打印机查询队列、smbclient的more命令以及cmbclient的mput命令的symlink攻击来覆盖任意文件。 漏洞英文描述: Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient. 漏洞参考: Reference: BUGTRAQ:20010417 Samba 2.0.8 security fix Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0305.html Reference: DEBIAN:DSA-048 Reference: URL:http://www.debian.org/security/2001/dsa-048 Reference: CALDERA:CSSA-2001-01 系统类型:其他 漏洞类型:权限有效性检查错误