多个供应商mtr漏洞

漏洞信息详情

多个供应商mtr漏洞

漏洞简介

mtr程序在尝试放弃特权时只使用一个seteuid调用。本地用户利用此漏洞可以提升根特权。

漏洞公告

Users of mtr should upgrade to version mtr-0.42 or later. An interim solution may be to remove the setuid bit. This will prevent non-root users from being able to gain any root privileges, although it will affect their use of mtr.
TurboLinux has issued a new package to fix this problem in versions 6.0.2 and prior.

参考网址

来源: BID
名称: 1038
链接:http://www.securityfocus.com/bid/1038

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享