积极预防 及时发现
快速响应 力保恢复
Mailman 是一个免费的基于Web的邮件列表管理软件包,用Perl语言实现,可运行于Unix/L...
发布时间:2002-03-12 信息来源:管理员

CNCVE编号:CNCVE-20020058 CVE编号: 安全级别:高 漏洞中文描述: Mailman 是一个免费的基于Web的邮件列表管理软件包,用Perl语言实现,可运行于Unix/Linux 类操作系统下。Mailman存在输入验证漏洞,可以使远程攻击者在主机上执行任意命令。Mailman对用户输入未作充分过滤而提交给open()系统调用,远程攻击者可以在输入中混入特定的shell转定字符,从而在目标主机上执行任意命令。先前版本的Mailman可能也存在类似的漏洞。 漏洞英文描述: Mailman Free is a web based mailing list management package implemented in Perl. It may safely be assumed to run under Linux and most Unix derived operating systems. Mailman passes user supplied input to an open() command, allowing remote attackers to execute arbitrary commands as the user nobody. Exploitation of this vulnerability may lead to local access. It is possible Mailman Pro and earlier verisons of the product share this vulnerability, although this has not been confirmed. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0153.html 系统类型:其他 漏洞类型:输入有效性检查错误