CNCVE编号:CNCVE-20010421 CVE编号:CAN-2001-0421 安全级别:中 漏洞中文描述: Solaris8及其早期版本中的FTP服务器允许本地和远程的攻击者引发一个root目录的核心卸载,可以用CWD~等命令用无效的口令获得有效的用户名,他们能泄漏诸如shadow中的口令或者磁盘中的敏感信息。 漏洞英文描述: FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could leak shadow password and sensitive message in disk. 漏洞参考: Reference: BUGTRAQ:20010417 Re: SUN SOLARIS 5.6/5.7 FTP Globbing Exploit ! Reference: URL:http://www.securityfocus.com/archive/1/177200 Reference: BID:2601 Reference: URL:http://www.securityfocus.com/bid/2601 系统类型:其他 漏洞类型:配置错误