积极预防 及时发现
快速响应 力保恢复
Solaris的mail实现可以允许一个攻击者以root身份执行任意代码。当一个suid进程通过ma...
发布时间:2002-03-11 信息来源:管理员

CNCVE编号:CNCVE-20020050 CVE编号: 安全级别:中 漏洞中文描述: Solaris的mail实现可以允许一个攻击者以root身份执行任意代码。当一个suid进程通过mail调用sendmail时在某些环境下这个缺陷可以被利用。比如给sendmail传递额外的命令行选项,可能就会破坏进程。In.lpd是Solaris默认安装下仅有此漏洞的程序,当然,一些第三方的软件可能也存在这个漏洞。 漏洞英文描述: The implementation of mail shipped with Solaris may allow an attacker to execute arbitrary code as the root user. The flaw may be exploited in some circumstances when a suid process calls sendmail through mail. It is possible, in this case, to pass additional command line options to sendmail, potentially subverting the process. The flaw with in.lpd, published as BID 3274, is an example of this problem. In.lpd is the only vulnerable program that is installed with Solaris by default. However, it is possible that third party software shares this vulnerability. 漏洞参考: http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F42774&zone_32=42774 系统类型:其他 漏洞类型:输入有效性检查错误