积极预防 及时发现
快速响应 力保恢复
当用户使用Unix(SFU)2.0服务的Telnet客户端时,Internet Explorer 6...
发布时间:2001-10-30 信息来源:管理员

CNCVE编号:CNCVE-20010667 CVE编号:CAN-2001-0667 安全级别:高 漏洞中文描述: 当用户使用Unix(SFU)2.0服务的Telnet客户端时,Internet Explorer 6及其早期版本允许远程攻击者通过用命令行中的日志文件选项的spawning telnet并且将任意的代码写入可执行文件中,从而执行命令。 漏洞英文描述: Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file option on the command line and writing arbitrary code into an executable file。 漏洞参考: Reference: MS:MS01-051 Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS01-051.asp 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:环境错误