漏洞信息详情
多个Linux供应商userhelper/PAM路径漏洞
- CNNVD编号:CNNVD-200001-018
- 危害等级: 高危
- CVE编号:
CVE-2000-0052
- 漏洞类型:
输入验证
- 发布时间:
2000-01-04
- 威胁类型:
本地
- 更新时间:
2005-05-02
- 厂 商:
mandrakesoft - 漏洞来源:
This was posted to… -
漏洞简介
Red Hat usermode包中的userhelper程序存在漏洞。本地用户可以借助PAM和..(点 点)攻击提升根访问权。
漏洞公告
RedHat released the following patches for this problem:
Intel:
ftp://updates.redhat.com/6.1/i386/pam-0.68-10.i386.rpm
ftp://updates.redhat.com/6.1/i386/usermode-1.17-1.i386.rpm
Alpha:
ftp://updates.redhat.com/6.1/alpha/pam-0.68-10.alpha.rpm
ftp://updates.redhat.com/6.1/alpha/usermode-1.17-1.alpha.rpm
Sparc:
ftp://updates.redhat.com/6.1/sparc/pam-0.68-10.sparc.rpm
ftp://updates.redhat.com/6.1/sparc/usermode-1.17-1.sparc.rpm
Source packages:
ftp://updates.redhat.com/6.1/SRPMS/pam-0.68-10.src.rpm
ftp://updates.redhat.com/6.1/SRPMS/usermode-1.17-1.src.rpm
TurboLinux has released patches for this vulnerability. Further information is available at
http://www.turbolinux.com/security
Turbolinux Turbolinux 6.0.2
-
TurboLinux pam-0.72-3.i386.rpm
ftp://ftp.turbolinux.com/pub/updates/6.0/security/pam-0.72-3.i386.rpm -
TurboLinux usermode-1.18-1.i386.rpm
ftp://ftp.turbolinux.com/pub/updates/6.0/security/usermode-1.18-1.i386
.rpm
参考网址
来源: XF
名称: linux-pam-userhelper
链接:http://xforce.iss.net/search.php3?type=2&pattern=linux-pam-userhelper
来源: BID
名称: 913
链接:http://www.securityfocus.com/bid/913
来源: REDHAT
名称: RHSA-2000:001
链接:http://www.redhat.com/support/errata/RHSA-2000-001.html
来源: L0PHT
名称: 20000104 PamSlam
链接:http://www.l0pht.com/advisories/pam_advisory