CNCVE编号:CNCVE-20020028 CVE编号: 安全级别:高 漏洞中文描述: Ecartis是Listar软件的新名字,Listar是一个邮件列表管理软件包,运行于Linux、BSD和其他Unix类操作系统下。Ecartis软件实现上存在缓冲区溢出漏洞,可能使远程攻击者通过溢出攻击在主机上执行任意指令。Ecartis对用户输入未做充分过滤,远程攻击者可能通过提交精心构造的数据给服务器,可能导致缓冲区溢出使攻击者执行任意指令,通常Listar是以listar用户的身份执行的,所以攻击者可能得到一般本地普通用户访问权限。 漏洞英文描述: Ecartis is the new name for the Listar software product. Listar is a mailing list management package for Linux, BSD, and other Unix like operating systems. A vulnerability has been announced in some versions of Ecartis and Listar. It is possible for user supplied input to overflow a buffer. This may result in stack data being overwritten with user supplied values, including the return address of a function call. If successfully exploited, this may result in the execution of arbitrary code. Listar normally runs as the non-privileged user 'listar'. However, exploitation of this vulnerability may result in local access for an attacker. From a local standpoint, further elevation of privileges may be easier to obtain. 漏洞参考: http://marc.10east.com/?l=listar-announce&m=101452659032650&w=2 系统类型:其他 漏洞类型:缓冲区溢出