积极预防 及时发现
快速响应 力保恢复
Sendmail 8.10.0到8.11.5以及8.12.0 beta版允许本地用户通过debugg...
发布时间:2001-09-20 信息来源:管理员

CNCVE编号:CNCVE-20010653 CVE编号:CAN-2001-0653 安全级别:中 漏洞中文描述: Sendmail 8.10.0到8.11.5以及8.12.0 beta版允许本地用户通过debugger命令行参数中的“category”部分设置为一个大值,使其被解释为一个负数,从而修改进程内存并有可能获得权限。 漏洞英文描述: Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privileges via a large value in the 'category' part of debugger (-d) command line arguments, which is interpreted as a negative number. 漏洞参考: Reference: BUGTRAQ:20010821 *ALERT* UPDATED BID 3163 (URGENCY 6.58): Sendmail Debugger Arbitrary Code Execution Vulnerability (fwd) Reference: URL: Reference: CONFIRM: