SANE不安全临时文件创建漏洞

漏洞信息详情

SANE不安全临时文件创建漏洞

漏洞简介

SANE library 1.0.3及其更早版本的某个后端驱动在前端软件如XSane使用时存在漏洞。本地用户可以借助临时文件上的符号链接攻击修改文件。

漏洞公告

This issue has been addressed in SANE 1.0.7-beta1 and later. Additional upgrades are also available.
Conectiva Linux has released an advisory (CLA-2003:769) to address this issue. Please see the referenced advisory for more information.
SANE SANE 1.0 .0

SANE SANE 1.0.1

SANE SANE 1.0.2

SANE SANE 1.0.3

SANE SANE 1.0.4

SANE SANE 1.0.5

参考网址

来源: XF
名称: xsane-temp-symlink(7714)
链接:http://www.iss.net/security_center/static/7714.php

来源: REDHAT
名称: RHSA-2001:171
链接:http://rhn.redhat.com/errata/RHSA-2001-171.html

来源: BID
名称: 3987
链接:http://www.securityfocus.com/bid/3987

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享