漏洞信息详情
BMC Patrol SNMP Agent文件创建/许可漏洞
- CNNVD编号:CNNVD-199907-015 <!--
- 危害等级: 高危-->
- 危害等级: 高危
- CVE编号: CVE-1999-1460
- 漏洞类型: 输入验证
- 发布时间: 1999-07-13
- 威胁类型: 本地
- 更新时间: 2005-10-20
- 厂 商: bmc
- 漏洞来源: on July 14, 1999. Parts of the discussion were taken directly from Andrew's BugTraq posting. Graeme Byrnes a Technical Support Specialist at BMC Software snet fix informatio');">First posted to Bu...
-
漏洞简介
BMC PATROL SNMP Agent 3.2.07之前的版本存在漏洞。本地用户可以通过指定目标文件作为snmpmagt程序的第二参数,来将任意全域可写文件创建为根。
漏洞公告
The solution for this issue is to upgrade to a release of the BMC PATROL product higher than 3.2.05. That is, this issue is limited to PATROL Version 3.2 to 3.2.05 only - all versions 3.2.07 and higher, including PATROL Version 3.3.xx, are OK.
参考网址
来源: BID 名称: 525 链接:http://www.securityfocus.com/bid/525 来源: BUGTRAQ 名称: 19990713 Root Perms Gained with Patrol SNMP Agent 3.2 (all others?) 链接:http://marc.theaimsgroup.com/?l=bugtraq&m=93198293132463&w=2 来源: BUGTRAQ 名称: 19990801 Re: Root Perms Gained with Patrol SNMP Agent 3.2 (all others?) 链接:http://marc.theaimsgroup.com/?l=bugtraq&m=93372579004129&w=2
受影响实体
- Bmc Patrol_agent:3.2<!--2000-1-1-->
- Bmc Patrol_agent:3.2.3<!--2000-1-1-->
- Bmc Patrol_agent:3.2.5<!--2000-1-1-->
- Bmc Patrol_agent:3.2.7<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...