漏洞信息详情
GnuPG格式字符串漏洞
- CNNVD编号:CNNVD-200108-049
- 危害等级: 高危
- CVE编号:
CVE-2001-0522
- 漏洞类型:
格式化字符串
- 发布时间:
2001-08-14
- 威胁类型:
远程
- 更新时间:
2005-05-02
- 厂 商:
gnu - 漏洞来源:
Reported to Bugtra… -
漏洞简介
Gnu Privacy Guard (也称为GnuPG或gpg) 1.05版本及之前版本存在格式字符串漏洞。攻击者可以借助存于加密文件内原始文件名中的格式字符串来提升特权。
漏洞公告
A new version of GnuPG is available which addresses these issues:
GNU GNU Privacy Guard 1.0.4
-
Caldera OpenLinux 3.1 Server i386 gnupg-1.0.6-1.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Server/current/RPMS/gn
upg-1.0.6-1.i386.rpm -
Caldera OpenLinux 3.1 Workstation i386 gnupg-1.0.6-1.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Workstation/current/RP
MS/gnupg-1.0.6-1.i386.rpm -
Conectiva 4.0 i386 gnupg-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.0/i386/gnupg-1.0.6-1cl.i386.rpm -
Conectiva 4.0 i386 gnupg-doc-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.0/i386/gnupg-doc-1.0.6-1cl.i386.
rpm -
Conectiva 4.0es i386 gnupg-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.0es/i386/gnupg-1.0.6-1cl.i386.rp
m -
Conectiva 4.0es i386 gnupg-doc-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.0es/i386/gnupg-doc-1.0.6-1cl.i38
6.rpm -
Conectiva 4.1 i386 gnupg-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.1/i386/gnupg-1.0.6-1cl.i386.rpm -
Conectiva 4.1 i386 gnupg-doc-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.1/i386/gnupg-doc-1.0.6-1cl.i386.
rpm -
Conectiva 4.2 i386 gnupg-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.2/i386/gnupg-1.0.6-1cl.i386.rpm -
Conectiva 4.2 i386 gnupg-doc-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.2/i386/gnupg-doc-1.0.6-1cl.i386.
rpm -
Conectiva 5.0 i386 gnupg-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.0/i386/gnupg-1.0.6-1cl.i386.rpm -
Conectiva 5.0 i386 gnupg-doc-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.0/i386/gnupg-doc-1.0.6-1cl.i386.
rpm -
Conectiva 5.1 i386 gnupg-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.1/i386/gnupg-1.0.6-1cl.i386.rpm -
Conectiva 5.1 i386 gnupg-doc-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.1/i386/gnupg-doc-1.0.6-1cl.i386.
rpm -
Conectiva 6.0 i386 gnupg-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/gnupg-1.0.6-1cl.i386.rpm -
Conectiva 6.0 i386 gnupg-doc-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/gnupg-doc-1.0.6-1cl.i386.
rpm -
Conectiva ecommerce i386 gnupg-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/ecommerce/i386/gnupg-1
.0.6-1cl.i386.rpm -
Conectiva ecommerce i386 gnupg-doc-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/ecommerce/i386/gnupg-d
oc-1.0.6-1cl.i386.rpm -
Conectiva graficas i386 gnupg-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/graficas/i386/gnupg-1.
0.6-1cl.i386.rpm -
Conectiva graficas i386 gnupg-doc-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/graficas/i386/gnupg-do
c-1.0.6-1cl.i386.rpm -
RedHat 7.1 i386 gnupg-1.0.6-1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/gnupg-1.0.6-1.i386.rpm -
TurboLinux 6.0 i386 gnupg-1.0.6-1.i386.rpm
ftp://ftp.turbolinux.com/pub/updates/6.0/security/gnupg-1.0.6-1.i386.r
pm
GNU GNU Privacy Guard 1.0.5
-
Caldera eDesktop 2.4 i386 gnupg-1.0.6-1.i386.rpm
ftp://ftp.caldera.com/pub/updates/eDesktop/2.4/current/RPMS/gnupg-1.0.
6-1.i386.rpm -
Caldera OpenLinux 2.3 gnupg-1.0.6-1.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/2.3/current/RPMS/gnupg-1.0
.6-1.i386.rpm -
Conectiva 4.0 i386 gnupg-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.0/i386/gnupg-1.0.6-1cl.i386.rpm -
Conectiva 4.0 i386 gnupg-doc-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.0/i386/gnupg-doc-1.0.6-1cl.i386.
rpm -
Conectiva 4.0es i386 gnupg-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.0es/i386/gnupg-1.0.6-1cl.i386.rp
m -
Conectiva 4.0es i386 gnupg-doc-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.0es/i386/gnupg-doc-1.0.6-1cl.i38
6.rpm -
Conectiva 4.1 i386 gnupg-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.1/i386/gnupg-1.0.6-1cl.i386.rpm -
Conectiva 4.1 i386 gnupg-doc-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.1/i386/gnupg-doc-1.0.6-1cl.i386.
rpm -
Conectiva 4.2 i386 gnupg-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.2/i386/gnupg-1.0.6-1cl.i386.rpm -
Conectiva 4.2 i386 gnupg-doc-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.2/i386/gnupg-doc-1.0.6-1cl.i386.
rpm -
Conectiva 5.0 i386 gnupg-1.0.6-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.0/i386/gnupg-1.0.6-1cl.i386.rpm - Co
参考网址
来源:US-CERT Vulnerability Note: VU#403051
名称: VU#403051
链接:http://www.kb.cert.org/vuls/id/403051
来源: MANDRAKE
名称: MDKSA-2001:053
链接:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-053.php3
来源: www.gnupg.org
链接:http://www.gnupg.org/whatsnew.html#rn20010529
来源: XF
名称: gnupg-tty-format-string(6642)
链接:http://xforce.iss.net/static/6642.php
来源: TURBO
名称: TLSA2001028
链接:http://www.turbolinux.com/pipermail/tl-security-announce/2001-June/000439.html
来源: BID
名称: 2797
链接:http://www.securityfocus.com/bid/2797
来源: REDHAT
名称: RHSA-2001:073
链接:http://www.redhat.com/support/errata/RHSA-2001-073.html
来源: OSVDB
名称: 1845
链接:http://www.osvdb.org/1845
来源: SUSE
名称: SuSE-SA:2001:020
链接:http://www.novell.com/linux/security/advisories/2001_020_gpg_txt.html
来源: DEBIAN
名称: DSA-061
链接:http://www.debian.org/security/2001/dsa-061
来源: CALDERA
名称: CSSA-2001-020.0
链接:http://www.calderasystems.com/support/security/advisories/CSSA-2001-020.0.txt
来源: BUGTRAQ
名称: 20010601 The GnuPG format string bug (was: TSLSA-2001-0009 – GnuPG)
链接:http://online.securityfocus.com/archive/1/188218
来源: IMMUNIX
名称: IMNX-2001-70-023-01
链接:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-023-01
来源: CONECTIVA
名称: CLA-2001:399
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000399