漏洞信息详情
多个供应商man(1) ‘makewhatis’不安全/tmp文件漏洞
- CNNVD编号:CNNVD-200007-003
- 危害等级: 高危
- CVE编号:
CVE-2000-0566
- 漏洞类型:
其他
- 发布时间:
2000-07-03
- 威胁类型:
本地
- 更新时间:
2005-05-02
- 厂 商:
redhat - 漏洞来源:
This problem was d… -
漏洞简介
Linux man程序包中的makewhatis存在漏洞。本地用户可以借助符号连接攻击来覆盖文件。
漏洞公告
Linux-Mandrake users (from the Advisory):
Please upgrade to:
md5sum: f4f87cab84a716a2ccb8c74b3325c0c9 6.0/RPMS/man-1.5g-15mdk.i586.rpm
md5sum: 52d021732aa09d517eeff8b60d427a69 6.0/SRPMS/man-1.5g-15mdk.src.rpm
md5sum: 2b01457036a6813fa616adbca97fcb36 6.1/RPMS/man-1.5g-15mdk.i586.rpm
md5sum: 52d021732aa09d517eeff8b60d427a69 6.1/SRPMS/man-1.5g-15mdk.src.rpm
md5sum: ea883685faa409148f9b55c442a0438c 7.0/RPMS/man-1.5g-15mdk.i586.rpm
md5sum: 52d021732aa09d517eeff8b60d427a69 7.0/SRPMS/man-1.5g-15mdk.src.rpm
md5sum: fbc1b9e04d75f267650f291d99f467f1 7.1/RPMS/man-1.5g-15mdk.i586.rpm
md5sum: 52d021732aa09d517eeff8b60d427a69 7.1/SRPMS/man-1.5g-15mdk.src.rpm
To upgrade automatically, use < MandrakeUpdate >. If you want to upgrade
manually, download the updated package from one of our FTP server mirrors
and uprade with “rpm -Uvh package_name”. All mirrors are listed on
http://www.mandrake.com/en/ftp.php3. Updated packages are available in the
“updates/” directory.
For example, if you are looking for an updated RPM package for Mandrake 7.1,
look for it in: updates/7.1/RPMS/
Trustix Secure Linux:
URLs:
Binary:
http://www.trustix.net/download/Trustix/updates/1.1/RPMS/man-1.5g-11tr.i586.rpm
ftp://ftp.trustix.com/pub/Trustix/updates/1.1/RPMS/man-1.5g-11tr.i586.rpm
Source:
http://www.trustix.net/download/Trustix/updates/1.1/SRPMS/man-1.5g-11tr.src.rpm
ftp://ftp.trustix.com/pub/Trustix/updates/1.1/SRPMS/man-1.5g-11tr.src.rpm
RedHat man-1.5f-1.i386.rpm
-
Red Hat Inc. 5.2 i386 man-1.5h1-2.5.x.i386.rpm
ftp://updates.redhat.com/5.2/i386/man-1.5h1-2.5.x.i386.rpm
RedHat man-1.5h1-1.i386.rpm
-
Red Hat Inc. 6.2 i386 man-1.5h1-2.6.x.i386.rpm
ftp://updates.redhat.com/6.2/i386/man-1.5h1-2.6.x.i386.rpm
Caldera OpenLinux 2.3
-
Caldera man-1.5f-6.i386.rpm
ftp://ftp.calderasystems.com/pub/updates/OpenLinux/2.3/current/RPMS/
Caldera OpenLinux 2.4
-
Caldera man-1.5f-6.i386.rpm
ftp://ftp.calderasystems.com/pub/updates/OpenLinux/2.3/current/RPMS/
RedHat Linux 5.2 alpha
-
Red Hat Inc. 5.2 alpha man-1.5h1-2.5.x.alpha.rpm
ftp://updates.redhat.com/5.2/alpha/man-1.5h1-2.5.x.alpha.rpm
RedHat Linux 5.2 i386
-
Red Hat Inc. 5.2 i386 man-1.5h1-2.5.x.i386.rpm
ftp://updates.redhat.com/5.2/i386/man-1.5h1-2.5.x.i386.rpm
RedHat Linux 5.2 sparc
-
Red Hat Inc. 5.2 sparc man-1.5h1-2.5.x.sparc.rpm
ftp://updates.redhat.com/5.2/sparc/man-1.5h1-2.5.x.sparc.rpm
RedHat Linux 6.2 alpha
-
Red Hat Inc. 6.2 alpha man-1.5h1-2.6.x.alpha.rpm
ftp://updates.redhat.com/6.2/alpha/man-1.5h1-2.6.x.alpha.rpm
RedHat Linux 6.2 i386
-
Red Hat Inc. 6.2 i386 man-1.5h1-2.6.x.i386.rpm
ftp://updates.redhat.com/6.2/i386/man-1.5h1-2.6.x.i386.rpm
RedHat Linux 6.2 sparc
-
Red Hat Inc. 6.2 sparc man-1.5h1-2.6.x.sparc.rpm
ftp://updates.redhat.com/6.2/sparc/man-1.5h1-2.6.x.sparc.rpm
参考网址
来源: XF
名称: linux-man-makewhatis-tmp
链接:http://xforce.iss.net/static/4900.php
来源: BID
名称: 1434
链接:http://www.securityfocus.com/bid/1434
来源: REDHAT
名称: RHSA-2000:041
链接:http://www.redhat.com/support/errata/RHSA-2000-041.html
来源: MANDRAKE
名称: MDKSA-2000:015
链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:015
来源: BUGTRAQ
名称: 20000727 CONECTIVA LINUX SECURITY ANNOUNCEMENT – MAN
链接:http://archives.neohapsis.com/archives/bugtraq/2000-07/0390.html
来源: CALDERA
名称: CSSA-2000-021.0
链接:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-021.0.txt