多个Linux供应商userhelper/PAM路径漏洞

漏洞信息详情

多个Linux供应商userhelper/PAM路径漏洞

漏洞简介

Red Hat usermode包中的userhelper程序存在漏洞。本地用户可以借助PAM和..(点 点)攻击提升根访问权。

漏洞公告

RedHat released the following patches for this problem:
Intel:
ftp://updates.redhat.com/6.1/i386/pam-0.68-10.i386.rpm
ftp://updates.redhat.com/6.1/i386/usermode-1.17-1.i386.rpm
Alpha:
ftp://updates.redhat.com/6.1/alpha/pam-0.68-10.alpha.rpm
ftp://updates.redhat.com/6.1/alpha/usermode-1.17-1.alpha.rpm
Sparc:
ftp://updates.redhat.com/6.1/sparc/pam-0.68-10.sparc.rpm
ftp://updates.redhat.com/6.1/sparc/usermode-1.17-1.sparc.rpm
Source packages:
ftp://updates.redhat.com/6.1/SRPMS/pam-0.68-10.src.rpm
ftp://updates.redhat.com/6.1/SRPMS/usermode-1.17-1.src.rpm
TurboLinux has released patches for this vulnerability. Further information is available at
http://www.turbolinux.com/security
Turbolinux Turbolinux 6.0.2

参考网址

来源: XF
名称: linux-pam-userhelper
链接:http://xforce.iss.net/search.php3?type=2&pattern=linux-pam-userhelper

来源: BID
名称: 913
链接:http://www.securityfocus.com/bid/913

来源: REDHAT
名称: RHSA-2000:001
链接:http://www.redhat.com/support/errata/RHSA-2000-001.html

来源: L0PHT
名称: 20000104 PamSlam
链接:http://www.l0pht.com/advisories/pam_advisory

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享