CNCVE编号:CNCVE-20000703 CVE编号:CVE-2000-0703 安全级别:中 漏洞中文描述: suidperl (这就是sperl)在调用/bin/mail发送错误报告时没有完全净化出口序列"~!",这可导致本地攻击者通过设置"interactive"环境变量和调用带有包含出口序列的文件名的suidperl来得到权限。 漏洞英文描述: suidperl (aka sperl) does not properly cleanse the escape sequence "~!" before calling /bin/mail to send an error report, which allows local users to gain privileges by setting the "interactive" environmental variable and calling suidperl with a filename 漏洞参考: 系统类型:其他 漏洞类型:其他