Caldera Open管理系统漏洞

漏洞信息详情

Caldera Open管理系统漏洞

漏洞简介

Caldera Open Administration System (COAS)存在一个漏洞,允许/etc/shadow密码文件全域可读。

漏洞公告

The proper solution is to upgrade to the coas-1.0-8 package. If /etc/shadow is world-readable, this is fixed with
chmod 600 /etc/shadow
The upgrade packages can be found on Caldera’s FTP site at:
ftp://ftp.calderasystems.com/pub/OpenLinux/updates/2.2/current/RPMS/
The corresponding source code package can be found at:
ftp://ftp.calderaystems.com/pub/OpenLinux/updates/2.2/current/SRPMS

参考网址

Vulnerable software and versionsConfiguration 1OR* cpe:/a:caldera:coas:1.0.5* cpe:/a:caldera:coas:1.0.6* cpe:/a:caldera:coas:1.0.7Configuration 2OR* cpe:/o:caldera:openlinux:2.2* Denotes Vulnerable Software* Changes related to vulnerability configurations

Technical DetailsVulnerability Type (View All)
CVE Standard Vulnerability Entry:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0712

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享