FCheck Shell Metacharacter in...

- AV AC AU C I A
发布: 2000-04-03
修订: 2025-04-13

FCheck, when invoked with the -l switch, will send reports to syslog instead of stdout. In the course of doing so, it makes a system() call with the filename in the argument. Therefore, if a filename contains a shell metacharacter followed by a command, that command will be executed at the privilege level of FCheck (usually root). Any user who can create files in a filestructure that is monitored by FCheck can exploit this vulnerability.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息