Symantec AntiVirus Scan Engine For Red Hat Linux不安全临时文件漏洞

漏洞信息详情

Symantec AntiVirus Scan Engine For Red Hat Linux不安全临时文件漏洞

漏洞简介

Red Hat Linux 中的Symantec AntiVirus Scan Engine 4.0和4.3版本LiveUpdate (liveupdate.sh)功能存在漏洞。本地用户可以通过/tmp/LiveUpdate.log文件上的链接攻击创建或追加任意文件。

漏洞公告

A build update for Symantec AntiVirus Scan Engine 4.3 correcting this issue is available. Users can obtain the update through their support channels. An update for Symantec Java LiveUpdate that is strengthened against this issue will be available soon.
An advisory detailing the remediation of this vulnerability is available at:
http://www.symantec.com/avcenter/security/Content/2004.03.23.html

参考网址

来源: XF
名称: symantec-scanengine-race-condition(15215)
链接:http://xforce.iss.net/xforce/xfdb/15215

来源: BID
名称: 9662
链接:http://www.securityfocus.com/bid/9662

来源: BUGTRAQ
名称: 20040216 Possible race condition in Symantec AntiVirus Scan Engine for Red
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=107694800908164&w=2

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享