CNCVE编号:CNCVE-20020054 CVE编号: 安全级别:高 漏洞中文描述: UnixWare是一个商业Unix操作系统,最初由SCO开发,现在由Caldera维护与分发。一些默认安装的UnixWare存在一个漏洞。UnixWare的/var/adm/isl/ifile文件包含了属主用户和root用户的加密口令,而且这个文件是全局可读的。一个本地用户可以访问这些信息,得到root的加密口令。 漏洞英文描述: UnixWare is a commercially available Unix Operating System. It was originally developed by SCO, and is now distributed and maintained by Caldera. A vulnerability has been reported in the default installation of some versions of UnixWare. A file exists which is world readable and includes the encrypted owner and root passwords. A local user would be able to access this information, and may be able to mount a dictionary attack on the root password without detection. The vulnerable file is /var/adm/isl/ifile. It is not currently known if this is a configuration error, or if this file reflects the current state of a changed root password. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0118.html ftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.5.1 系统类型:其他 漏洞类型:设计错误