积极预防 及时发现
快速响应 力保恢复
Horde IMP 2.2.4 及其早期版本允许本地用户通过对临时文件上的symlink攻击来阅读任...
发布时间:2001-10-18 信息来源:管理员

CNCVE编号:CNCVE-20010744 CVE编号:CAN-2001-0744 安全级别:中 漏洞中文描述: Horde IMP 2.2.4 及其早期版本允许本地用户通过对临时文件上的symlink攻击来阅读任意文件。 漏洞英文描述: Horde IMP 2.2.4 and earlier allows local users to overwrite files via a symlink attack on a temporary file. 漏洞参考: Reference: BUGTRAQ:20010531 Imp-2.2.4 temporary files Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0303.html Reference: CONFIRM:http://www.horde.org/imp/2.2/news.php Reference: CALDERA:CSSA-2001-025.0 Reference: URL:http:/ 系统类型:其他 漏洞类型:权限有效性检查错误