CNCVE编号:CNCVE-20020053 CVE编号: 安全级别:高 漏洞中文描述: Astaro Security Linux是一个开放源码的防火墙。它由Astaro开发和维护。Astaro Security Linux使用了一些不安全的文件和目录权限。本地用户缺省可以对一些敏感的系统文件进行写操作,而Astaro Security Linux是为防火墙实现设计的,并非多用户系统,这会造成一个非特权的用户可以对那些系统文件和目录进行恶意的操作。非特权的用户还可能通过shell访问系统,进行SSH中间人攻击,修改rpm校验码给系统安装木马,以及一些其它的恶意操作。 漏洞英文描述: Astaro Security Linux is an open source firewall implementation. It is developed and maintained by Astaro. Astaro Security Linux uses an insecure set of file and directory permissions. In a default implementation, sensitive system files are writeable by local users. While Astaro Security Linux is designed as a firewall implementation, and not a multi-user system, the design could allow an unprivileged user that has gained access to the system to take advantage of these file and directory permissions to perform nefarious activities. This problem makes it possible for an unprivileged user with access to the system via a shell to obscure their activity, perform an SSH man-in-the-middle attack, alter rpm checksums and potentially exploit the system with a trojaned rpm file, or other malicious activity. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0145.html http://www.astaro.com/ 系统类型:其他 漏洞类型:设计错误