多个供应商man(1) ‘makewhatis’不安全/tmp文件漏洞

漏洞信息详情

多个供应商man(1) ‘makewhatis’不安全/tmp文件漏洞

漏洞简介

Linux man程序包中的makewhatis存在漏洞。本地用户可以借助符号连接攻击来覆盖文件。

漏洞公告

Linux-Mandrake users (from the Advisory):
Please upgrade to:
md5sum: f4f87cab84a716a2ccb8c74b3325c0c9 6.0/RPMS/man-1.5g-15mdk.i586.rpm
md5sum: 52d021732aa09d517eeff8b60d427a69 6.0/SRPMS/man-1.5g-15mdk.src.rpm
md5sum: 2b01457036a6813fa616adbca97fcb36 6.1/RPMS/man-1.5g-15mdk.i586.rpm
md5sum: 52d021732aa09d517eeff8b60d427a69 6.1/SRPMS/man-1.5g-15mdk.src.rpm
md5sum: ea883685faa409148f9b55c442a0438c 7.0/RPMS/man-1.5g-15mdk.i586.rpm
md5sum: 52d021732aa09d517eeff8b60d427a69 7.0/SRPMS/man-1.5g-15mdk.src.rpm
md5sum: fbc1b9e04d75f267650f291d99f467f1 7.1/RPMS/man-1.5g-15mdk.i586.rpm
md5sum: 52d021732aa09d517eeff8b60d427a69 7.1/SRPMS/man-1.5g-15mdk.src.rpm
To upgrade automatically, use < MandrakeUpdate >. If you want to upgrade
manually, download the updated package from one of our FTP server mirrors
and uprade with “rpm -Uvh package_name”. All mirrors are listed on
http://www.mandrake.com/en/ftp.php3. Updated packages are available in the
“updates/” directory.
For example, if you are looking for an updated RPM package for Mandrake 7.1,
look for it in: updates/7.1/RPMS/
Trustix Secure Linux:
URLs:
Binary:
http://www.trustix.net/download/Trustix/updates/1.1/RPMS/man-1.5g-11tr.i586.rpm
ftp://ftp.trustix.com/pub/Trustix/updates/1.1/RPMS/man-1.5g-11tr.i586.rpm
Source:
http://www.trustix.net/download/Trustix/updates/1.1/SRPMS/man-1.5g-11tr.src.rpm
ftp://ftp.trustix.com/pub/Trustix/updates/1.1/SRPMS/man-1.5g-11tr.src.rpm
RedHat man-1.5f-1.i386.rpm

RedHat man-1.5h1-1.i386.rpm

Caldera OpenLinux 2.3

Caldera OpenLinux 2.4

RedHat Linux 5.2 alpha

RedHat Linux 5.2 i386

RedHat Linux 5.2 sparc

RedHat Linux 6.2 alpha

RedHat Linux 6.2 i386

RedHat Linux 6.2 sparc

参考网址

来源: XF
名称: linux-man-makewhatis-tmp
链接:http://xforce.iss.net/static/4900.php

来源: BID
名称: 1434
链接:http://www.securityfocus.com/bid/1434

来源: REDHAT
名称: RHSA-2000:041
链接:http://www.redhat.com/support/errata/RHSA-2000-041.html

来源: MANDRAKE
名称: MDKSA-2000:015
链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:015

来源: BUGTRAQ
名称: 20000727 CONECTIVA LINUX SECURITY ANNOUNCEMENT – MAN
链接:http://archives.neohapsis.com/archives/bugtraq/2000-07/0390.html

来源: CALDERA
名称: CSSA-2000-021.0
链接:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-021.0.txt

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享