Ypbind -ypset/-ypsetme缓冲区溢出漏洞

漏洞信息详情

Ypbind -ypset/-ypsetme缓冲区溢出漏洞

漏洞简介

Linux Slackware和SunOS激活-ypset和-ypsetme选项的ypbind存在漏洞。本地用户和远程攻击者可以通过..(点 点)攻击覆盖文件。

漏洞公告

From the Network Associates advisory:
We suggest that you not invoke ypbind with either the -ypset or -ypsetme options. It would be better practice to define which NIS clients may bind to which NIS servers in local configuration files.

参考网址

来源: NAI
名称: 19970205 Vulnerabilities in Ypbind when run with -ypset/-ypsetme
链接:http://www.nai.com/nai_labs/asp_set/advisory/06_ypbindsetme_adv.asp

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享