漏洞信息详情
William Deich Super SysLog 格式化字符串漏洞
- CNNVD编号:CNNVD-200208-122
- 危害等级: 高危
- CVE编号:
CVE-2002-0817
- 漏洞类型:
格式化字符串
- 发布时间:
2002-08-12
- 威胁类型:
本地
- 更新时间:
2005-05-02
- 厂 商:
william_deich - 漏洞来源:
Discovery credited… -
漏洞简介
Linux的super存在格式化字符串漏洞。本地用户可以借助超长命令行参数提升根特权。
漏洞公告
FreeBSD has released a Security Notice FreeBSD-SN-02:05. Users of FreeBSD systems are strongly urged to upgrade their ports tree to fix various reported issues. Further information can be found in the referenced Security Notice.
Fixes available:
William Deich super 3.12
-
Debian super_3.12.2-2.1_alpha.debDebian 2.2 Alpha.
http://security.debian.org/pool/updates/main/s/super/super_3.12.2-2.1_
alpha.deb -
Debian super_3.12.2-2.1_arm.debDebian 2.2 ARM.
http://security.debian.org/pool/updates/main/s/super/super_3.12.2-2.1_
arm.deb -
Debian super_3.12.2-2.1_i386.debDebian 2.2 i386.
http://security.debian.org/pool/updates/main/s/super/super_3.12.2-2.1_
i386.deb -
Debian super_3.12.2-2.1_m68k.debDebian 2.2 m68k.
http://security.debian.org/pool/updates/main/s/super/super_3.12.2-2.1_
m68k.deb -
Debian super_3.12.2-2.1_powerpc.debDebian 2.2 PPC.
http://security.debian.org/pool/updates/main/s/super/super_3.12.2-2.1_
powerpc.deb -
Debian super_3.12.2-2.1_sparc.debDebian 2.2 sparc.
http://security.debian.org/pool/updates/main/s/super/super_3.12.2-2.1_
sparc.deb -
William Deich super-3.19.0.tar.gz
ftp://ftp.ucolick.org/pub/users/will/super-3.19.0.tar.gz
William Deich super 3.16
-
Debian super_3.16.1-1.1_alpha.debDebian 3.0 Alpha.
http://security.debian.org/pool/updates/main/s/super/super_3.16.1-1.1_
alpha.deb -
Debian super_3.16.1-1.1_hppa.debDebian 3.0 HPPA.
http://security.debian.org/pool/updates/main/s/super/super_3.16.1-1.1_
hppa.deb -
Debian super_3.16.1-1.1_i386.debDebian 3.0 i386.
http://security.debian.org/pool/updates/main/s/super/super_3.16.1-1.1_
i386.deb -
Debian super_3.16.1-1.1_ia64.debDebian 3.0 IA64.
http://security.debian.org/pool/updates/main/s/super/super_3.16.1-1.1_
ia64.deb -
Debian super_3.16.1-1.1_m68k.debDebian 3.0 m68k.
http://security.debian.org/pool/updates/main/s/super/super_3.16.1-1.1_
m68k.deb -
Debian super_3.16.1-1.1_mips.debDebian 3.0 MIPS.
http://security.debian.org/pool/updates/main/s/super/super_3.16.1-1.1_
mips.deb -
Debian super_3.16.1-1.1_mipsel.debDebian 3.0 MIPS (little endian).
http://security.debian.org/pool/updates/main/s/super/super_3.16.1-1.1_
mipsel.deb -
Debian super_3.16.1-1.1_powerpc.debDebian 3.0 PPC.
http://security.debian.org/pool/updates/main/s/super/super_3.16.1-1.1_
powerpc.deb -
Debian super_3.16.1-1.1_sparc.debDebian 3.0.
http://security.debian.org/pool/updates/main/s/super/super_3.16.1-1.1_
sparc.deb -
William Deich super-3.19.0.tar.gz
ftp://ftp.ucolick.org/pub/users/will/super-3.19.0.tar.gz
William Deich super 3.17
-
William Deich super-3.19.0.tar.gz
ftp://ftp.ucolick.org/pub/users/will/super-3.19.0.tar.gz
William Deich super 3.18
-
William Deich super-3.19.0.tar.gz
ftp://ftp.ucolick.org/pub/users/will/super-3.19.0.tar.gz
参考网址
来源: DEBIAN
名称: DSA-139
链接:http://www.debian.org/security/2002/dsa-139
来源: BUGTRAQ
名称: 20020731 The SUPER Bug
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=102812622416695&w=2
来源: BID
名称: 5367
链接:http://www.securityfocus.com/bid/5367
来源: XF
名称: super-syslog-format-string(9741)
链接:http://www.iss.net/security_center/static/9741.php
来源: VULNWATCH
名称: 20020730 The SUPER Bug
链接:http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0045.html