漏洞信息详情
Pine畸形标题服务拒绝漏洞
- CNNVD编号:CNNVD-200011-003
- 危害等级: 高危
- CVE编号:
CVE-2000-0847
- 漏洞类型:
缓冲区溢出
- 发布时间:
2000-11-14
- 威胁类型:
远程
- 更新时间:
2005-05-02
- 厂 商:
university_of_washington - 漏洞来源:
First made public … -
漏洞简介
Washington大学c-client库*(被用于pine和其他程序)存在缓冲区溢出漏洞。远程攻击者可以借助超长X-Keywords标题来执行任意命令。
漏洞公告
RedHat, FreeBSD and Mandrake have released patches for this vulnerability:
University of Washington Pine 4.0.4
-
Red Hat Inc. 5.2 alpha imap-2000-2.5.alpha.rpm
ftp://updates.redhat.com/5.2/alpha/imap-2000-2.5.alpha.rpm -
Red Hat Inc. 5.2 alpha imap-devel-2000-2.5.alpha.rpm
ftp://updates.redhat.com/5.2/alpha/imap-devel-2000-2.5.alpha.rpm -
Red Hat Inc. 5.2 i386 imap-2000-2.5.i386.rpm
ftp://updates.redhat.com/5.2/i386/imap-2000-2.5.i386.rpm -
Red Hat Inc. 5.2 i386 imap-devel-2000-2.5.i386.rpm
ftp://updates.redhat.com/5.2/i386/imap-devel-2000-2.5.i386.rpm -
Red Hat Inc. 5.2 sparc imap-2000-2.5.sparc.rpm
ftp://updates.redhat.com/5.2/sparc/imap-2000-2.5.sparc.rpm -
Red Hat Inc. 5.2 sparc imap-devel-2000-2.5.sparc.rpm
ftp://updates.redhat.com/5.2/sparc/imap-devel-2000-2.5.sparc.rpm -
RedHat 5.2 (i386): pine-4.30-1.52
ftp://updates.redhat.com/5.2/i386/pine-4.30-1.52.i386.rpm -
RedHat 5.2 (Sparc): pine-4.30-1.52
ftp://updates.redhat.com/5.2/sparc/pine-4.30-1.52.sparc.rpm
University of Washington Pine 4.10
-
MandrakeSoft 6.0 i386 pine-4.30-3.3mdk.i586.rpm
http://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/updates/6.0/RPMS/
pine-4.30-3.3mdk.i586.rpm -
MandrakeSoft 6.1 i386 pine-4.30-3.3mdk.i586.rpm
http://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/updates/6.1/RPMS/
pine-4.30-3.3mdk.i586.rpm -
MandrakeSoft 7.0 i386 pine-4.30-3.3mdk.i586.rpm
http://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/updates/7.0/RPMS/
pine-4.30-3.3mdk.i586.rpm -
Red Hat Inc. 6.0 alpha imap-2000-2.6.alpha.rpm
ftp://updates.redhat.com/6.0/alpha/imap-2000-2.6.alpha.rpm -
Red Hat Inc. 6.0 alpha imap-devel-2000-2.6.alpha.rpm
ftp://updates.redhat.com/6.0/alpha/imap-devel-2000-2.6.alpha.rpm -
Red Hat Inc. 6.0 i386 imap-2000-2.6.i386.rpm
ftp://updates.redhat.com/6.0/i386/imap-2000-2.6.i386.rpm -
Red Hat Inc. 6.0 i386 imap-devel-2000-2.6.i386.rpm
ftp://updates.redhat.com/6.0/i386/imap-devel-2000-2.6.i386.rpm -
Red Hat Inc. 6.0 sparc imap-2000-2.6.sparc.rpm
ftp://updates.redhat.com/6.0/sparc/imap-2000-2.6.sparc.rpm -
Red Hat Inc. 6.0 sparc imap-devel-2000-2.6.sparc.rpm
ftp://updates.redhat.com/6.0/sparc/imap-devel-2000-2.6.sparc.rpm -
Red Hat Inc. 6.1 alpha imap-2000-2.6.alpha.rpm
ftp://updates.redhat.com/6.1/alpha/imap-2000-2.6.alpha.rpm -
Red Hat Inc. 6.1 alpha imap-devel-2000-2.6.alpha.rpm
ftp://updates.redhat.com/6.1/alpha/imap-devel-2000-2.6.alpha.rpm -
Red Hat Inc. 6.1 alpha pine-4.30-1.62.alpha.rpm
ftp://updates.redhat.com/6.1/alpha/pine-4.30-1.62.alpha.rpm -
Red Hat Inc. 6.1 i386 imap-2000-2.6.i386.rpm
ftp://updates.redhat.com/6.1/i386/imap-2000-2.6.i386.rpm -
Red Hat Inc. 6.1 i386 imap-devel-2000-2.6.i386.rpm
ftp://updates.redhat.com/6.1/i386/imap-devel-2000-2.6.i386.rpm -
Red Hat Inc. 6.1 i386 pine-4.30-1.62.i386.rpm
ftp://updates.redhat.com/6.1/i386/pine-4.30-1.62.i386.rpm -
Red Hat Inc. 6.1 sparc imap-2000-2.6.sparc.rpm
ftp://updates.redhat.com/6.1/sparc/imap-2000-2.6.sparc.rpm -
Red Hat Inc. 6.1 sparc imap-devel-2000-2.6.sparc.rpm
ftp://updates.redhat.com/6.1/sparc/imap-devel-2000-2.6.sparc.rpm -
Red Hat Inc. 6.1 sparc pine-4.30-1.62.sparc.rpm
ftp://updates.redhat.com/6.1/sparc/pine-4.30-1.62.sparc.rpm -
RedHat 6.0 (Alpha): pine-4.30-1.62
ftp://updates.redhat.com/6.0/alpha/pine-4.30-1.62.alpha.rpm -
RedHat 6.0 (i386): pine-4.30-1.62
ftp://updates.redhat.com/6.0/i386/pine-4.30-1.62.i386.rpm -
RedHat 6.0 (Sparc): pine-4.30-1.62
ftp://updates.redhat.com/6.0/sparc/pine-4.30-1.62.sparc.rpm
University of Washington Pine 4.21
-
FreeBSD ports-3 pine-4.21
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-3-stable/mail/pi
ne-4.21.tgz -
FreeBSD ports-4 alpha pine-4.21
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/alpha/packages-4-stable/mail/p
ine-4.21.tgz -
FreeBSD ports-4 i386 pine-4.21
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-4-stable/mail/pi
ne-4.21.tgz -
FreeBSD ports-5 alpha pine-4.21
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/alpha/packages-5-current/mail/
pine-4.21.tgz -
FreeBSD ports-5 i386 pine-4.21
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-5-current/mail/p
ine-4.21.tgz -
MandrakeSoft 7.1 i386 pine-4.30-3.2mdk.i586.rpm
http://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/updates/7.1/RPMS/
pine-4.30-3.2mdk.i586.rpm -
MandrakeSoft 7.2 i386 pine-4.30-3.1mdk.i586.rpm
参考网址
来源: BID
名称: 1646
链接:http://www.securityfocus.com/bid/1646来源: BUGTRAQ
名称: 20000901 More about UW c-client library
链接:http://archives.neohapsis.com/archives/bugtraq/2000-08/0437.html来源: XF
名称: c-client-dos(5223)
链接:http://xforce.iss.net/xforce/xfdb/5223来源: BID
名称: 1687
链接:http://www.securityfocus.com/bid/1687来源: FREEBSD
名称: FreeBSD-SA-00:47.pine
链接:http://archives.neohapsis.com/archives/freebsd/2000-09/0108.html来源: BUGTRAQ
名称: 20000901 UW c-client library vulnerability
链接:http://archives.neohapsis.com/archives/bugtraq/2000-08/0425.html