AIX frcactrl 非安全文件处理漏洞。

漏洞信息详情

AIX frcactrl 非安全文件处理漏洞。

漏洞简介

AIX Fast Response Cache Accelerator (FRCA)存在漏洞,本地用户可以通过frcactrl程序的配置能力修改任意文件。

漏洞公告

Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com.
A suitable work around is to remove the setuid bit from the frcactrl program, and unload the FRCA kernel module:
# /usr/sbin/frcactrl unload ; /usr/sbin/slibclean
# chmod 555 /usr/sbin/frcactrl
IBM AIX 4.3

IBM AIX 4.3.1

IBM AIX 4.3.2

参考网址

来源: ISS
名称: 20000426 Insecure file handling in IBM AIX frcactrl program
链接:http://xforce.iss.net/alerts/advise47.php3

来源: BID
名称: 1152
链接:http://www.securityfocus.com/bid/1152

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享