HP JetAdmin符号链接漏洞

漏洞信息详情

HP JetAdmin符号链接漏洞

漏洞简介

Solaris的HP JetAdmin D.01.09中存在漏洞,本地用户借助/tmp/jetadmin.log文件中的符号连接攻击改变任意文件的许可权限。

漏洞公告

HP recommends upgrading to a later version of the jetadmin software, available at
http://www.hp.com/go/support, in the Network Printing section.
Posts to Bugtraq suggested changing line 17 to set more restrictive permissions. However, the potential still exists for a powerful denial of service should this be the option selected.

参考网址

来源: BUGTRAQ
名称: 19980722 Re: JetAdmin software
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104526067&w=2

来源: BUGTRAQ
名称: 19980715 JetAdmin software
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104525988&w=2

来源: BID
名称: 157
链接:http://www.securityfocus.com/bid/157

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享