This just means that the program checked if a situation was OK, then later used that information, but an attacker can change the situation between those two steps.
这只说明了程序检查某种情形是否可行,然后稍后使用那一信息,但是攻击者可能会在这两个步骤之间改变该情形。
If the file is specified by setting the INFORMIXSQLHOSTS environment variable, then the owner and group are not checked, but public write permissions are not permitted.
如果用INFORMIXSQLHOSTS环境变量设置该文件,则不检查所有者和组,但是仍然不允许对其使用公共写权限。
Sendmail checked that "debug flag" values weren't larger than the legal value, but it didn't check if the number was negative.
sendmail会检查“调试标记”是不是比合法的值大,但是它并没有去检查这个值是不是负数。
应用推荐