积极预防 及时发现
快速响应 力保恢复
OpenSSH当UseLogin选项允许时没有完全释放权限,这可导致本地用户通过向ssh后台程序提供...
发布时间:2002-05-20 信息来源:管理员

CNCVE编号:CNCVE-20000525 CVE编号:CVE-2000-0525 安全级别:中 漏洞中文描述: OpenSSH当UseLogin选项允许时没有完全释放权限,这可导致本地用户通过向ssh后台程序提供命令来执行任意命令。 漏洞英文描述: OpenSSH does not properly drop privileges when the UseLogin option is enabled, which allows local users to execute arbitrary commands by providing the command to the ssh daemon. 漏洞参考: 系统类型:其他 漏洞类型:其他