Debian bsdmainutils 6.0.14 – Calendar Information Disclosure

Debian bsdmainutils 6.0.14 – Calendar Information Disclosure

漏洞ID 1054574 漏洞类型
发布时间 2004-08-31 更新时间 2004-08-31
图片[1]-Debian bsdmainutils 6.0.14 – Calendar Information Disclosure-安全小百科CVE编号 N/A
图片[2]-Debian bsdmainutils 6.0.14 – Calendar Information Disclosure-安全小百科CNNVD-ID N/A
漏洞平台 Linux CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/24421
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/11077/info

The calendar utility contained in the bsdmainutils package on Debian GNU/Linux systems is reported susceptible to an information disclosure vulnerability. This is due to a lack of proper file authorization checks by the application.

The application fails to enforce permissions of included files when run as the superuser with the '-a' argument, therefore it is possible for a local attacker to create a calendar file that will disclose the contents of arbitrary, potentially sensitive files. This may aid them in further attacks against the affected computer.

By default, the package is installed with a crontab file that will not call the calendar utility. Systems are only affected if the crontab is enabled by administrators.

Debian GNU/Linux computers with bsdmainutils versions prior to 6.0.15 are reported to be vulnerable. 

#define root Jun. 28<tab>cut_here
#include </etc/shadow>
Jun. 28<tab>Birthday of Steven Van Acker
Aug. 19<tab>Birthday of Andrew Griffith

(where <tab> should be replaced by an actual Tab character)

相关推荐: PY-Membres SQL注入漏洞

PY-Membres SQL注入漏洞 漏洞ID 1202411 漏洞类型 SQL注入 发布时间 2003-10-20 更新时间 2003-10-20 CVE编号 CVE-2003-0751 CNNVD-ID CNNVD-200310-037 漏洞平台 N/A …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享