积极预防 及时发现
快速响应 力保恢复
bash 2.0.0、 1.4.17及其他版本中的缓冲区溢出允许本地攻击者通过创建一个极大的目录名来...
发布时间:2002-05-20 信息来源:管理员

CNCVE编号:CNCVE-19991048 CVE编号:CVE-1999-1048 安全级别:中 漏洞中文描述: bash 2.0.0、 1.4.17及其他版本中的缓冲区溢出允许本地攻击者通过创建一个极大的目录名来获得权限,当另一用户变为此目录时,通过PS1环境变量中的w选项可以把它插入口令提示中。 漏洞英文描述: Buffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges by creating an extremely large directory name, which is inserted into the password prompt via the \w option in the PS1 environmental variable when another user use this directory. 漏洞参考: 系统类型:其他 漏洞类型:其他