Re: Microsoft FTP Client Multiple Bufferoverflow Vulnerability

看板Bugtraq作者時間18年前 (2007/11/30 07:28), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串4/5 (看更多)
Valdis.Kletnieks@vt.edu wrote: >> An attacker who can convince an user to extract a specially crafted >> archive can overwrite arbitrary files with the permissions of the user >> running gtar. If that user is root, the attacker can overwrite any >> file on the system. > > Apparently, somebody at FreeBSD thinks "can be exploited if you trick the > user into doing something" is a valid attack vector. The difference is that I'd be surprised when I got 0wned by unpacking an archive, and not all that surprised when I got 0wned by running a random executable (script) file.
文章代碼(AID): #17Jqi800 (Bugtraq)
討論串 (同標題文章)
文章代碼(AID): #17Jqi800 (Bugtraq)