积极预防 及时发现
快速响应 力保恢复
AIX 4.x 中的lsfs允许远程攻击者通过在用户控制下的某个目录中创立以grep或lslv命名的...
发布时间:2001-08-02 信息来源:管理员

CNCVE编号:CNCVE-20010573 CVE编号:CAN-2001-0573 安全级别:中 漏洞中文描述: AIX 4.x 中的lsfs允许远程攻击者通过在用户控制下的某个目录中创立以grep或lslv命名的特洛伊木马(Trojan horse)程序来获得额外的权限,这会导致lsfs有权访问此目录下的程序。 漏洞英文描述: lsfs in AIX 4.x allows a local user to gain additional privileges by creating Trojan horse programs named (1) grep or (2) lslv in a certain directory that is under the user's control, which cause lsfs to access the programs in that directory. 漏洞参考: Reference: AIX-APAR:IY16909 Reference: URL:http://archives.neohapsis.com/archives/aix/2001-q2/0000.html 系统类型:其他 漏洞类型:输入有效性检查错误