Lucene search

K
seebugRootSSV:4365
HistoryOct 28, 2008 - 12:00 a.m.

Lynx '.mailcap'和'.mime.type'文件本地代码执行漏洞

2008-10-2800:00:00
Root
www.seebug.org
22

EPSS

0

Percentile

0.4%

BUGTRAQ ID: 31917
CVE ID:CVE-2006-7234
CNCVE ID:CNCVE-20087234

Lynx是一款基于文本的浏览器。
Lynx处理’.mailcap’和’.mime.type’文件存在问题,本地攻击者可以利用漏洞以应用程序权限执行任意指令。
Lynx从当前目录中打开mailcap和mime类型定义文件,如果用户可以在特殊构建的目录中诱使用户运行lynx,攻击者可以控制目录以运行lynx用户权限执行任意代码。

University of Kansas Lynx 2.8.6 dev9
University of Kansas Lynx 2.8.6 dev8
University of Kansas Lynx 2.8.6 dev7
University of Kansas Lynx 2.8.6 dev6
University of Kansas Lynx 2.8.6 dev5
University of Kansas Lynx 2.8.6 dev4
University of Kansas Lynx 2.8.6 dev3
University of Kansas Lynx 2.8.6 dev2
University of Kansas Lynx 2.8.6 dev15
University of Kansas Lynx 2.8.6 dev14
University of Kansas Lynx 2.8.6 dev13
University of Kansas Lynx 2.8.6 dev12
University of Kansas Lynx 2.8.6 dev11
University of Kansas Lynx 2.8.6 dev10
University of Kansas Lynx 2.8.6 dev1
University of Kansas Lynx 2.8.6
University of Kansas Lynx 2.8.5 dev.8


                                                .mime.types:
application/x-bug bug
.mailcap:
application/x-bug; xmessage 'Hello, World!'