FreeBSD fingerd File Disclosure...

- AV AC AU C I A
发布: 2000-10-13
修订: 2025-04-13

A vulnerability exists in the version of fingerd that ships with FreeBSD 4.1.1-RELEASE. This vulnerability has to do with a feature that was added to fingerd allowing users to request the contents of certain files (administrator-specified) remotely, via the finger client. Unfortunately, the client can request the contents of any file or listing of any directory on the server's filesystem readable to user 'nobody', bypassing the access restrictions. The information obtained (eg. valid usernames, possibly cgi source code, http passwd files) may be used for more complicated/targeted attacks. fingerd sets its uid as 'nobody' and executes the finger client locally when opening the requested file. Because of this, reading the contents of "secure" files such as /etc/master.passwd is not possible via this vulnerability.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息