多个Linux厂商的imwheel漏洞

漏洞信息详情

多个Linux厂商的imwheel漏洞

漏洞简介

imwheel中存在缓冲区溢出漏洞,本地用户可以通过imwheel-solo脚本和超长HOME环境变量获得根用户权限。

漏洞公告

RedHat has made patches available for this problem.
Removal of the setuid wrapper script ‘imwheel-solo’ will eliminate this problem.
RedHat Linux 6.1 i386

RedHat Linux 6.1 sparc

RedHat Linux 6.1 alpha

RedHat Linux 6.2 sparc

RedHat Linux 6.2 i386

RedHat Linux 6.2 alpha

参考网址

来源: BID
名称: 1060
链接:http://www.securityfocus.com/bid/1060

来源: REDHAT
名称: RHSA-2000:016
链接:http://www.redhat.com/support/errata/RHSA-2000-016.html

来源: BUGTRAQ
名称: 20000316 TESO & C-Skills development advisory — imwheel
链接:http://archives.neohapsis.com/archives/bugtraq/2000-03/0168.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享