漏洞信息详情
Symantec AntiVirus Scan Engine For Red Hat Linux不安全临时文件漏洞
- CNNVD编号:CNNVD-200404-039
- 危害等级: 低危
- CVE编号:
CVE-2004-0217
- 漏洞类型:
竞争条件
- 发布时间:
2004-04-15
- 威胁类型:
本地
- 更新时间:
2006-08-16
- 厂 商:
symantec - 漏洞来源:
Discovery is credi… -
漏洞简介
Red Hat Linux 中的Symantec AntiVirus Scan Engine 4.0和4.3版本LiveUpdate (liveupdate.sh)功能存在漏洞。本地用户可以通过/tmp/LiveUpdate.log文件上的链接攻击创建或追加任意文件。
漏洞公告
A build update for Symantec AntiVirus Scan Engine 4.3 correcting this issue is available. Users can obtain the update through their support channels. An update for Symantec Java LiveUpdate that is strengthened against this issue will be available soon.
An advisory detailing the remediation of this vulnerability is available at:
http://www.symantec.com/avcenter/security/Content/2004.03.23.html
参考网址
来源: XF
名称: symantec-scanengine-race-condition(15215)
链接:http://xforce.iss.net/xforce/xfdb/15215
来源: BID
名称: 9662
链接:http://www.securityfocus.com/bid/9662
来源: BUGTRAQ
名称: 20040216 Possible race condition in Symantec AntiVirus Scan Engine for Red
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=107694800908164&w=2