积极预防 及时发现
快速响应 力保恢复
IBM IBMHSSSB 1.0中的ikeyman设置classpath环境变量时包括在系统目录前用...
发布时间:2001-08-31 信息来源:管理员

CNCVE编号:CNCVE-20001202 CVE编号:CAN-2000-1202 安全级别:高 漏洞中文描述: IBM IBMHSSSB 1.0中的ikeyman设置classpath环境变量时包括在系统目录前用户自己的CLASSPATH目录,这允许恶意的本地用户通过特洛伊木马Ikeyman类来执行任意文件。 漏洞英文描述: ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class. 漏洞参考: Reference: BUGTRAQ:20000405 minor issue with IBM HTTPD and /usr/bin/ikeyman Reference: URL:http://www.securityfocus.com/archive/1/54073 Reference: BID:1092 Reference: URL:http://www.securityfocus.com/bid/1092 Reference: XF:ibm-ikeyman(4235) Referen 系统类型:其他 漏洞类型:异常处理错误