漏洞信息详情
多厂商top格式化字符串漏洞
- CNNVD编号:CNNVD-200012-011
- 危害等级: 高危
- CVE编号:
CVE-2000-0998
- 漏洞类型:
格式化字符串
- 发布时间:
2000-12-11
- 威胁类型:
本地
- 更新时间:
2007-05-11
- 厂 商:
freebsd - 漏洞来源:
First published in… -
漏洞简介
top程序存在格式化字符串漏洞。本地攻击者可以借助“kill”或“renice”函数获取根权限。
漏洞公告
FreeBSD has released patches for this vulnerability.
The vendor has released version 3.5.1 of top to address this vulnerability.
William LeFebvre top 1.0
-
William LeFebvre top-3.5.1.tar.gz
http://prdownloads.sourceforge.net/unixtop/top-3.5.1.tar.gz?download
William LeFebvre top 1.2
-
William LeFebvre top-3.5.1.tar.gz
http://prdownloads.sourceforge.net/unixtop/top-3.5.1.tar.gz?download
William LeFebvre top 1.3
-
William LeFebvre top-3.5.1.tar.gz
http://prdownloads.sourceforge.net/unixtop/top-3.5.1.tar.gz?download
William LeFebvre top 1.4
-
William LeFebvre top-3.5.1.tar.gz
http://prdownloads.sourceforge.net/unixtop/top-3.5.1.tar.gz?download
William LeFebvre top 1.5
-
William LeFebvre top-3.5.1.tar.gz
http://prdownloads.sourceforge.net/unixtop/top-3.5.1.tar.gz?download
William LeFebvre top 1.6
-
William LeFebvre top-3.5.1.tar.gz
http://prdownloads.sourceforge.net/unixtop/top-3.5.1.tar.gz?download
William LeFebvre top 1.7
-
William LeFebvre top-3.5.1.tar.gz
http://prdownloads.sourceforge.net/unixtop/top-3.5.1.tar.gz?download
William LeFebvre top 1.8
-
William LeFebvre top-3.5.1.tar.gz
http://prdownloads.sourceforge.net/unixtop/top-3.5.1.tar.gz?download
William LeFebvre top 2.0
-
William LeFebvre top-3.5.1.tar.gz
http://prdownloads.sourceforge.net/unixtop/top-3.5.1.tar.gz?download
William LeFebvre top 2.0 pre
-
William LeFebvre top-3.5.1.tar.gz
http://prdownloads.sourceforge.net/unixtop/top-3.5.1.tar.gz?download
William LeFebvre top 2.0.11
-
William LeFebvre top-3.5.1.tar.gz
http://prdownloads.sourceforge.net/unixtop/top-3.5.1.tar.gz?download
William LeFebvre top 2.1
-
William LeFebvre top-3.5.1.tar.gz
http://prdownloads.sourceforge.net/unixtop/top-3.5.1.tar.gz?download
William LeFebvre top 3.5
-
William LeFebvre top-3.5.1.tar.gz
http://prdownloads.sourceforge.net/unixtop/top-3.5.1.tar.gz?download
FreeBSD FreeBSD 4.0
-
FreeBSD 3.x/4.x: top.patchThis patch should fix all vulnerable versions.Execute the following commands as root:# cd /usr/src/contrib/top# patch -p < /path/to/patch_or_advisory# cd /usr/src/usr.bin/top# make depend && make all install
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/patches/SA-00:62/top.patch.v1.1
参考网址
来源: BID
名称: 1895
链接:http://www.securityfocus.com/bid/1895
来源: FREEBSD
名称: FreeBSD-SA-00:62
链接:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:62.top.v1.1.asc
来源: ftp.openbsd.org
链接:ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch