多厂商top格式化字符串漏洞

漏洞信息详情

多厂商top格式化字符串漏洞

漏洞简介

top程序存在格式化字符串漏洞。本地攻击者可以借助“kill”或“renice”函数获取根权限。

漏洞公告

FreeBSD has released patches for this vulnerability.
The vendor has released version 3.5.1 of top to address this vulnerability.
William LeFebvre top 1.0

William LeFebvre top 1.2

William LeFebvre top 1.3

William LeFebvre top 1.4

William LeFebvre top 1.5

William LeFebvre top 1.6

William LeFebvre top 1.7

William LeFebvre top 1.8

William LeFebvre top 2.0

William LeFebvre top 2.0 pre

William LeFebvre top 2.0.11

William LeFebvre top 2.1

William LeFebvre top 3.5

FreeBSD FreeBSD 4.0

参考网址

来源: BID
名称: 1895
链接:http://www.securityfocus.com/bid/1895

来源: FREEBSD
名称: FreeBSD-SA-00:62
链接:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:62.top.v1.1.asc

来源: ftp.openbsd.org
链接:ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享