积极预防 及时发现
快速响应 力保恢复
各种Linux系统版本上的sendfiled包含Simple Asychronous File Tr...
发布时间:2001-08-02 信息来源:管理员

CNCVE编号:CNCVE-20010623 CVE编号:CAN-2001-0623 安全级别:中 漏洞中文描述: 各种Linux系统版本上的sendfiled包含Simple Asychronous File Transfer时,不能在发送签名邮件后正确的注销权限,这允许本地攻击者获得权限。 漏洞英文描述: sendfiled, as included with Simple Asynchronous File Transfer (SAFT), on various Linux systems does not properly drop privileges when sending notification emails, which allows local attackers to gain privileges. 漏洞参考: Reference: DEBIAN:DSA-052 Reference: URL:http://www.debian.org/security/2001/dsa-052 Reference: XF:saft-sendfiled-execute-code(6430) Reference: URL:http://xforce.iss.net/static/6430.php 系统类型:其他 漏洞类型:设计错误