William Deich Super SysLog 格式化字符串漏洞

漏洞信息详情

William Deich Super SysLog 格式化字符串漏洞

漏洞简介

Linux的super存在格式化字符串漏洞。本地用户可以借助超长命令行参数提升根特权。

漏洞公告

FreeBSD has released a Security Notice FreeBSD-SN-02:05. Users of FreeBSD systems are strongly urged to upgrade their ports tree to fix various reported issues. Further information can be found in the referenced Security Notice.
Fixes available:
William Deich super 3.12

William Deich super 3.16

William Deich super 3.17

William Deich super 3.18

参考网址

来源: DEBIAN
名称: DSA-139
链接:http://www.debian.org/security/2002/dsa-139

来源: BUGTRAQ
名称: 20020731 The SUPER Bug
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=102812622416695&w=2

来源: BID
名称: 5367
链接:http://www.securityfocus.com/bid/5367

来源: XF
名称: super-syslog-format-string(9741)
链接:http://www.iss.net/security_center/static/9741.php

来源: VULNWATCH
名称: 20020730 The SUPER Bug
链接:http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0045.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享