多个Linux供应商restore缓冲区溢出漏洞

漏洞信息详情

多个Linux供应商restore缓冲区溢出漏洞

漏洞简介

dump包中restore程序0.4b17和更早的版本存在缓冲区溢出漏洞。本地用户借助超长磁带名称可以执行任意命令。

漏洞公告

The package has been patched by its maintainer, and a new version released.
Linux-Mandrake 6.0:
828d750c80c021c6253cac0191486fb1 6.0/RPMS/dump-0.4b18-1mdk.i586.rpm
3e6355619c5ee93ac3505efdb35831fe 6.0/RPMS/rmt-0.4b18-1mdk.i586.rpm
4ff0d0a768b603f22a40745da303e365 6.0/SRPMS/dump-0.4b18-1mdk.src.rpm
Linux-Mandrake 6.1:
5a6587e3320eefb639ff4dad95e291be 6.1/RPMS/dump-0.4b18-1mdk.i586.rpm
582e35490586bcf04f1d35dcb04b6b23 6.1/RPMS/rmt-0.4b18-1mdk.i586.rpm
4ff0d0a768b603f22a40745da303e365 6.1/SRPMS/dump-0.4b18-1mdk.src.rpm
Linux-Mandrake 7.0:
6f9918a61ced3dd8d20cf2b9b34508d8 7.0/RPMS/dump-0.4b18-1mdk.i586.rpm
59c52401e9eb452fe9876d99cf2448bf 7.0/RPMS/rmt-0.4b18-1mdk.i586.rpm
4ff0d0a768b603f22a40745da303e365 7.0/SRPMS/dump-0.4b18-1mdk.src.rpm
Linux-Mandrake 7.1:
1c14f72e09d69fcd4645ea2bd80c4ab3 7.1/RPMS/dump-0.4b18-1mdk.i586.rpm
6d419e7e52dda174f7250b1b59c6b614 7.1/RPMS/rmt-0.4b18-1mdk.i586.rpm
4ff0d0a768b603f22a40745da303e365 7.1/SRPMS/dump-0.4b18-1mdk.src.rpm
To upgrade automatically, use < MandrakeUpdate >
If you want to upgrade manually, download the updated package from one
of our FTP server mirrors and uprade with “rpm -Uvh package_name”.
You can download the updates directly from:
ftp://ftp.linux.tucows.com/pub/distributions/Mandrake/Mandrake/updates
ftp://ftp.free.fr/pub/Distributions_Linux/Mandrake/updates
Stelian Pop dump 0.4 b15-30

Stelian Pop dump 0.4 b16-0

Stelian Pop dump 0.4 b9-9

Stelian Pop dump 0.4 b17-0

Stelian Pop dump 0.4 b9-0

Stelian Pop dump 0.4 b15-1

参考网址

来源: BID
名称: 1330
链接:http://www.securityfocus.com/bid/1330

来源: bugzilla.redhat.com
链接:http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=11880

来源: BUGTRAQ
名称: 20000630 CONECTIVA LINUX SECURITY ANNOUNCEMENT – dump
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=96240393814071&w=2

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享