CNCVE编号:CNCVE-20010625 CVE编号:CAN-2001-0625 安全级别:高 漏洞中文描述: Computer Associates InoculateIT 6.0 中的ftpdownload 允许本地用户通过一个对tmp/ftpdownload.log 上的symlink攻击来覆盖任意文件。 漏洞英文描述: ftpdownload in Computer Associates InoculateIT 6.0 allows a local attacker to overwrite arbitrary files via a symlink attack on /tmp/ftpdownload.log . 漏洞参考: Reference: BUGTRAQ:20010525 Security Bug in InoculateIT for Linux (fwd) Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0245.html Reference: XF:inoculateit-ftpdownload-symlink(6607) Reference: URL:http://xforce.iss.net/static/66 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误