FreeBSD Security Advisory 2002.7...

- AV AC AU C I A
发布: 2002-01-19
修订: 2025-04-13

FreeBSD Security Advisory FreeBSD-SA-02:07 - The k5su command included with FreeBSD, versions prior to 4.5-RELEASE, and the su command included in the heimdal port, versions prior to heimdal-0.4e_2, use the getlogin system call in order to determine whether the currently logged-in user is 'root'. In some circumstances, it is possible for a non-privileged process to have 'root' as the login name returned by getlogin. You don't actually want that to happen, trust us.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息