漏洞信息详情
多个Linux供应商restore缓冲区溢出漏洞
- CNNVD编号:CNNVD-200006-031
- 危害等级: 高危
- CVE编号:
CVE-2000-0520
- 漏洞类型:
缓冲区溢出
- 发布时间:
2000-06-07
- 威胁类型:
本地
- 更新时间:
2005-10-20
- 厂 商:
stelian - 漏洞来源:
This vulnerability… -
漏洞简介
dump包中restore程序0.4b17和更早的版本存在缓冲区溢出漏洞。本地用户借助超长磁带名称可以执行任意命令。
漏洞公告
The package has been patched by its maintainer, and a new version released.
Linux-Mandrake 6.0:
828d750c80c021c6253cac0191486fb1 6.0/RPMS/dump-0.4b18-1mdk.i586.rpm
3e6355619c5ee93ac3505efdb35831fe 6.0/RPMS/rmt-0.4b18-1mdk.i586.rpm
4ff0d0a768b603f22a40745da303e365 6.0/SRPMS/dump-0.4b18-1mdk.src.rpm
Linux-Mandrake 6.1:
5a6587e3320eefb639ff4dad95e291be 6.1/RPMS/dump-0.4b18-1mdk.i586.rpm
582e35490586bcf04f1d35dcb04b6b23 6.1/RPMS/rmt-0.4b18-1mdk.i586.rpm
4ff0d0a768b603f22a40745da303e365 6.1/SRPMS/dump-0.4b18-1mdk.src.rpm
Linux-Mandrake 7.0:
6f9918a61ced3dd8d20cf2b9b34508d8 7.0/RPMS/dump-0.4b18-1mdk.i586.rpm
59c52401e9eb452fe9876d99cf2448bf 7.0/RPMS/rmt-0.4b18-1mdk.i586.rpm
4ff0d0a768b603f22a40745da303e365 7.0/SRPMS/dump-0.4b18-1mdk.src.rpm
Linux-Mandrake 7.1:
1c14f72e09d69fcd4645ea2bd80c4ab3 7.1/RPMS/dump-0.4b18-1mdk.i586.rpm
6d419e7e52dda174f7250b1b59c6b614 7.1/RPMS/rmt-0.4b18-1mdk.i586.rpm
4ff0d0a768b603f22a40745da303e365 7.1/SRPMS/dump-0.4b18-1mdk.src.rpm
To upgrade automatically, use < MandrakeUpdate >
If you want to upgrade manually, download the updated package from one
of our FTP server mirrors and uprade with “rpm -Uvh package_name”.
You can download the updates directly from:
ftp://ftp.linux.tucows.com/pub/distributions/Mandrake/Mandrake/updates
ftp://ftp.free.fr/pub/Distributions_Linux/Mandrake/updates
Stelian Pop dump 0.4 b15-30
-
Stelian Pop dump-0.4b18
http://dump.sourceforge.net
Stelian Pop dump 0.4 b16-0
-
Stelian Pop dump-0.4b18
http://dump.sourceforge.net
Stelian Pop dump 0.4 b9-9
-
Stelian Pop dump-0.4b18
http://dump.sourceforge.net
Stelian Pop dump 0.4 b17-0
-
Stelian Pop dump-0.4b18
http://dump.sourceforge.net
Stelian Pop dump 0.4 b9-0
-
Stelian Pop dump-0.4b18
http://dump.sourceforge.net
Stelian Pop dump 0.4 b15-1
-
Stelian Pop dump-0.4b18
http://dump.sourceforge.net
参考网址
来源: BID
名称: 1330
链接:http://www.securityfocus.com/bid/1330
来源: bugzilla.redhat.com
链接:http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=11880
来源: BUGTRAQ
名称: 20000630 CONECTIVA LINUX SECURITY ANNOUNCEMENT – dump
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=96240393814071&w=2