Linux nfsd 远程缓冲区溢出漏洞

漏洞信息详情

Linux nfsd 远程缓冲区溢出漏洞

漏洞简介

基于Linux平台的NFS服务器存在缓冲区溢出漏洞。攻击者可以通过一个长路径名执行命令。

漏洞公告

A temporary solution is to remove the setuid bit from nfsd and/or stop the nfsd service.
A more long term solution is to upgrade to the newest version of nfsd for linux, since this has been fixed.
Slackware 4.0:
ftp.cdrom.com:/pub/linux/slackware-4.0/patches/nfs-server.tgz
Slackware 7.0:
ftp.cdrom.com:/pub/linux/slackware-7.0/patches/nfs-server.tgz
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com.

参考网址

来源: BUGTRAQ
名称: 19991109 undocumented bugs – nfsd
链接:http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.LNX.4.20.9911091058140.12964-100000@mail.zigzag.pl

来源: BID
名称: 782
链接:http://www.securityfocus.com/bid/782

来源: REDHAT
名称: RHSA-1999:053-01
链接:http://www.redhat.com/support/errata/rh42-errata-general.html#NFS

来源: SUSE
名称: 19991110 Security hole in nfs-server < 2.2beta47 within nkita
链接:http://www.novell.com/linux/security/advisories/suse_security_announce_29.html

来源: DEBIAN
名称: 19991111 buffer overflow in nfs server
链接:http://www.debian.org/security/1999/19991111

来源: CALDERA
名称: CSSA-1999-033.0
链接:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-033.0.txt

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享