漏洞信息详情
Linux cdrecord 缓冲区溢出漏洞
- CNNVD编号:CNNVD-200005-100
- 危害等级: 高危
- CVE编号:
CVE-2000-0454
- 漏洞类型:
缓冲区溢出
- 发布时间:
2000-05-29
- 威胁类型:
本地
- 更新时间:
2005-05-02
- 厂 商:
mandrakesoft - 漏洞来源:
First posted to Bu… -
漏洞简介
Linux cdrecord存在缓冲区溢出漏洞。本地用户借助dev参数可以提升特权。
漏洞公告
To upgrade automatically, use ? MandrakeUpdate ?. If you want to upgrade manually, download the updated package from one of the FTP server mirrors and uprade with “rpm -Uvh package_name”. All mirrors are listed on
http://www.mandrake.com/en/ftp.php3 Updated packages are available in the “updates/” directory.
For example, if you are looking for an updated RPM package for Mandrake 7.0, look for it in: updates/7.0/RPMS/
MandrakeSoft Linux Mandrake 7.0
-
MandrakeSoft 7.0 i386 cdrecord-1.8.1-4mdk.i586.rpm
http://www.mandrake.com/en/ftp.php3 -
MandrakeSoft 7.0 i386 cdrecord-cdda2wav-1.8.1-4mdk.i586.rpm
http://www.mandrake.com/en/ftp.php3 -
MandrakeSoft 7.0 i386 cdrecord-devel-1.8.1-4mdk.i586.rpm
http://www.mandrake.com/en/ftp.php3 -
MandrakeSoft 7.0 i386 mkisofs-1.12.1-4mdk.i586.rpm
http://www.mandrake.com/en/ftp.php3 -
MandrakeSoft 7.0 source cdrecord-1.8.1-4mdk.src.rpm
http://www.mandrake.com/en/ftp.php3
参考网址
来源: BID
名称: 1265
链接:http://www.securityfocus.com/bid/1265
来源: BUGTRAQ
名称: 20000607 Conectiva Linux Security Announcement – cdrecord
链接:http://archives.neohapsis.com/archives/bugtraq/2000-06/0019.html
来源: BUGTRAQ
名称: 20000603 [Gael Duval ] [Security Announce] cdrecord
链接:http://archives.neohapsis.com/archives/bugtraq/2000-05/0434.html
来源: BUGTRAQ
名称: 20000527 Mandrake 7.0: /usr/bin/cdrecord gid=80 (strike #2)
链接:http://archives.neohapsis.com/archives/bugtraq/2000-05/0367.html