积极预防 及时发现
快速响应 力保恢复
FreeBSD 4.2和4.3中的rmuser 工具,当更新原始文件时,创建带有全局可读许可的m...
发布时间:2002-05-20 信息来源:管理员

CNCVE编号:CNCVE-20011017 CVE编号:CVE-2001-1017 安全级别:中 漏洞中文描述: FreeBSD 4.2和4.3中的rmuser 工具,当更新原始文件时,创建带有全局可读许可的master.passwd文件的一个拷贝,这可能允许本地用户通过在rmuser运行时读取拷贝的文件来得到权限,还可以得到口令信号以及破坏口令。 漏洞英文描述: rmuser utility in FreeBSD 4.2 and 4.3 creates a copy of the master.passwd file with world-readable permissions while updating the original file, which could allow local users to gain privileges by reading the copied file while rmuser is running, obtain the password signal for corrupting it. 漏洞参考: 系统类型:其他 漏洞类型:其他