积极预防 及时发现
快速响应 力保恢复
一些在Unix上的实现现场子系统的函数不能完全净化user-injected格式化字符串,这导致本地...
发布时间:2002-05-20 信息来源:管理员

CNCVE编号:CNCVE-20000844 CVE编号:CVE-2000-0844 安全级别:中 漏洞中文描述: 一些在Unix上的实现现场子系统的函数不能完全净化user-injected格式化字符串,这导致本地用户可以通过例如gettext和catopen的函数来执行任意命令。 漏洞英文描述: Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen. 漏洞参考: 系统类型:其他 漏洞类型:其他