CNCVE编号:CNCVE-20010735 CVE编号:CAN-2001-0735 安全级别:高 漏洞中文描述: 当ALLOW_LINE_PARSING选项被激活时,cfingerd 1.4.3 及其早期版本中的缓冲区溢出允许本地用户通过 .nofinger文件中的一个长行来执行任意代码。 漏洞英文描述: Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute arbitrary code via a long line in the .nofinger file. 漏洞参考: Reference: BUGTRAQ:20010621 cfingerd local vulnerability (possibly root) Reference: URL:http://www.securityfocus.com/archive/1/192844 Reference: BUGTRAQ:20010711 Another exploit for cfingerd <= 1.4.3-8 Reference: URL:http://www.securityfocus.com/ar 系统类型:其他 漏洞类型:输入有效性检查错误