Progress Database Error Message File...

- AV AC AU C I A
发布: 2003-04-03
修订: 2025-04-13

Some Progress Database binaries are reportedly installed setuid root on Unix systems. It is possible for a local user to specify an arbitrary path to a configuration file via environment variables, which will be accessed with elevated privileges. If an error is encountered when opening the configuration file, the contents of the file are displayed in the error message. This could allow an unprivileged user to specify any file as the configuration file and view the contents through the Progress error message regardless of the privilege level of the target file.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息