积极预防 及时发现
快速响应 力保恢复
当使用sftp-server运行sftp和使用受限密钥对时,OpenSSH before 2.9.9...
发布时间:2001-12-06 信息来源:管理员

CNCVE编号:CNCVE-20010816 CVE编号:CAN-2001-0816 安全级别:高 漏洞中文描述: 当使用sftp-server运行sftp和使用受限密钥对时,OpenSSH before 2.9.9远程认证用户使用sftp命令来绕过authorized_keys2 command= restrictions。 漏洞英文描述: OpenSSH before 2.9.9, when running sftp using sftp-server and using restricted keypairs, allows remote authenticated users to bypass authorized_keys2 command= restrictions using sftp commands. 漏洞参考: Reference: BUGTRAQ:20010918 OpenSSH: sftp & bypassing keypair auth restrictions Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0153.html 系统类型:其他 漏洞类型:异常处理错误