isec-0008-sun-at.txt...

- AV AC AU C I A
发布: 2003-01-27
修订: 2025-04-13

The at utility in Solaris has name handling and race condition vulnerabilities. Using the -r switch to remove a job allows an attacker to remove any file on the filesystem as root. Although at filters out absolute paths, a simple ../ directory traversal maneuver allows an attacker to remove files out of the allowed boundary.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息