IMP/MSWordView /tmp文件许可漏洞

漏洞信息详情

IMP/MSWordView /tmp文件许可漏洞

漏洞简介

IMP的MSWordView应用软件在/tmp目录建立完全可读文件存在漏洞,其他本地用户可以利用这个漏洞读取潜在敏感信息。

漏洞公告

CThis vulnerability was fixed in versions 2.2-pre11 of IMP. Those wishing to utilize IMP 2.0.11 (the latest stable version) can work around this problem by creating a directory writable by the user MSWordView is run by (typically whoever the web server runs as), and altering the imp/lib/mimetypes.lib file to change t the directory temporary files are made in by MSWordView.
IMP IMP 2.0.10

IMP IMP 2.0.11

IMP IMP 2.0.9

IMP IMP 2.2 -pre9

IMP IMP 2.2 -pre10

参考网址

来源: BID
名称: 1360
链接:http://www.securityfocus.com/bid/1360

来源: BUGTRAQ
名称: 20000424 Two Problems in IMP 2
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=95672120116627&w=2

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享