积极预防 及时发现
快速响应 力保恢复
Computer Associates InoculateIT 6.0 中的ftpdownload ...
发布时间:2001-08-22 信息来源:管理员

CNCVE编号:CNCVE-20010625 CVE编号:CAN-2001-0625 安全级别:高 漏洞中文描述: Computer Associates InoculateIT 6.0 中的ftpdownload 允许本地用户通过一个对tmp/ftpdownload.log 上的symlink攻击来覆盖任意文件。 漏洞英文描述: ftpdownload in Computer Associates InoculateIT 6.0 allows a local attacker to overwrite arbitrary files via a symlink attack on /tmp/ftpdownload.log . 漏洞参考: Reference: BUGTRAQ:20010525 Security Bug in InoculateIT for Linux (fwd) Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0245.html Reference: XF:inoculateit-ftpdownload-symlink(6607) Reference: URL:http://xforce.iss.net/static/66 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误