xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
English Version

IRIX 'mv'存在不安全目录权限漏洞


发布时间:2002-10-11
更新时间:2002-10-11
严重程度:
威胁程度:其它
错误类型:设计错误
利用方式:服务器模式

BUGTRAQ ID:5893

受影响系统
SGI IRIX 6.5
SGI IRIX 6.5.1
SGI IRIX 6.5.2
SGI IRIX 6.5.3
SGI IRIX 6.5.4
SGI IRIX 6.5.5
SGI IRIX 6.5.6
SGI IRIX 6.5.7
SGI IRIX 6.5.8
SGI IRIX 6.5.9
SGI IRIX 6.5.10
SGI IRIX 6.5.11
SGI IRIX 6.5.12
SGI IRIX 6.5.13 m
SGI IRIX 6.5.13
SGI IRIX 6.5.14 m
SGI IRIX 6.5.14
SGI IRIX 6.5.15 m
SGI IRIX 6.5.15
SGI IRIX 6.5.16 m
SGI IRIX 6.5.16
SGI IRIX 6.5.17 m
SGI IRIX 6.5.17
详细描述
IRIX操作系统中的'mv'命令存在漏洞,默认安装。

'mv'命令在更改目录名的时候会导致建立不安全权限,可使其他一般用户访问敏感系统文件。

测试代码


解决方案
补丁下载:

SGI IRIX 6.5:

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.1:

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.2:

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.3:

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.4:

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.5:

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.6:

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.7:

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.8:

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.9:

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.10:

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.11:

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.12:

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.13 m:

SGI Patch patch4771.tar
ftp://patches.sgi.com/support/free/security/patches/

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.13:

SGI Patch patch4772.tar
ftp://patches.sgi.com/support/free/security/patches/

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.14 m:

SGI Patch patch4771.tar
ftp://patches.sgi.com/support/free/security/patches/

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.14:

SGI Patch patch4772.tar
ftp://patches.sgi.com/support/free/security/patches/

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.15 m:

SGI Patch patch4771.tar
ftp://patches.sgi.com/support/free/security/patches/

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.15:

SGI Patch patch4772.tar
ftp://patches.sgi.com/support/free/security/patches/

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.16 m:

SGI Patch patch4771.tar
ftp://patches.sgi.com/support/free/security/patches/

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.16:

SGI Patch patch4772.tar
ftp://patches.sgi.com/support/free/security/patches/

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.17 m:

SGI Patch patch4771.tar
ftp://patches.sgi.com/support/free/security/patches/

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

SGI IRIX 6.5.17:

SGI Patch patch4772.tar
ftp://patches.sgi.com/support/free/security/patches/

SGI Upgrade IRIX 6.5.18
http://www.sgi.com/software/software.html#IRIX

相关信息
参考:http://online.securityfocus.com/advisories/4526