Computer Security
[EN] securityvulns.ru
no-pyccku



DoS через GNU fileutils
Published:11.03.2002
Source:BUGTRAQ
SecurityVulns ID:1854
Type:local
Level:4/10
Описание:Если при удалении структуры каталогов типа ./a/b/c перенести каталог с в другой каталог будет удалена другая структура каталогов.
Affected:ORACLE : Solaris 8
 GNU : fileutils 4.1
 ORACLE : Solaris 9
 ORACLE : Solaris 10
CVE:CVE-2007-0895 (Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to delete files and directories as the user running rm by moving a low-level directory to a higher level as it is being deleted, which causes rm to chdir to a ".." directory that is higher than expected, possibly up to the root file system, a related issue to CVE-2002-0435.)
 CVE-2002-0435 (Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it is being deleted, which causes fileutils to chdir to a ".." directory that is higher than expected, possibly up to the root file system.)
Original documentdocumentWojciech Purczynski, GNU fileutils - recursive directory removal race condition (11.03.2002)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server