CNCVE编号:CNCVE-20031432 CVE编号: 安全级别:高 漏洞中文描述: GNATS包含的Queue-PR工具在处理命令行选项时缺少正确边界缓冲区检查,本地攻击者可以利用这个漏洞触发缓冲区溢出攻击,可以root用户权限在系统上执行任意指令。 漏洞英文描述: It has been reported that a script contained in paFileDB does not properly verify user credentials before accepting files for upload. As a result, remote attackers may be able to upload files to the Web server. After a file has been uploaded, it may be possible for the attacker to execute the file remotely. 漏洞参考: Reference: BUGTRAQ http://www.securityfocus.com/bid/8232 系统类型: Unix/Linux 漏洞类型:边界溢出