HP Tru64 NLSPATH环境变量本地缓冲区溢出漏洞

漏洞信息详情

HP Tru64 NLSPATH环境变量本地缓冲区溢出漏洞

漏洞简介

HP Tru64 UNIX存在多个缓冲区溢出漏洞。本地和可能的远程攻击者借助到(1)csh,(2)dtsession,(3)dxsysinfo,(4)imapd,(5) inc,(6)uucp,(7) uux,(8)rdist, 或者(9)deliver的超长NLSPATH环境变量执行任意代码。

漏洞公告

HP has released fixes for Tru64 UNIX/TruCluster systems. Note that appropriate patchkits must be applied.
Compaq Tru64 4.0 g PK3 (BL17)

Compaq Tru64 4.0 f PK7 (BL18)

Compaq Tru64 5.0 a PK3 (BL17)

Compaq Tru64 5.1 a PK2 (BL2)

Compaq Tru64 5.1 PK5 (BL19)

参考网址

来源:US-CERT Vulnerability Note: VU#846307
名称: VU#846307
链接:http://www.kb.cert.org/vuls/id/846307

来源:US-CERT Vulnerability Note: VU#592515
名称: VU#592515
链接:http://www.kb.cert.org/vuls/id/592515

来源:US-CERT Vulnerability Note: VU#584243
名称: VU#584243
链接:http://www.kb.cert.org/vuls/id/584243

来源:US-CERT Vulnerability Note: VU#567963
名称: VU#567963
链接:http://www.kb.cert.org/vuls/id/567963

来源:US-CERT Vulnerability Note: VU#531355
名称: VU#531355
链接:http://www.kb.cert.org/vuls/id/531355

来源:US-CERT Vulnerability Note: VU#448987
名称: VU#448987
链接:http://www.kb.cert.org/vuls/id/448987

来源:US-CERT Vulnerability Note: VU#437899
名称: VU#437899
链接:http://www.kb.cert.org/vuls/id/437899

来源:US-CERT Vulnerability Note: VU#416427
名称: VU#416427
链接:http://www.kb.cert.org/vuls/id/416427

来源:US-CERT Vulnerability Note: VU#158499
名称: VU#158499
链接:http://www.kb.cert.org/vuls/id/158499

来源: XF
名称: tru64-multiple-binaries-bo(10016)
链接:http://xforce.iss.net/xforce/xfdb/10016

来源: BUGTRAQ
名称: 20020902 Happy Labor Day from Snosoft
链接:http://www.securityfocus.com/archive/1/290115

来源: www.blacksheepnetworks.com
链接:http://www.blacksheepnetworks.com/security/hack/tru64/TRU64_nlspath.txt

来源: BUGTRAQ
名称: 20020919 iDEFENSE OSF1/Tru64 3.x vuln clarification
链接:http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html

来源: BID
名称: 5647
链接:http://www.securityfocus.com/bid/5647

来源: HP
名称: SSRT2275
链接:http://wwss1pro.compaq.com/support/reference_library/viewdocument.asp?source=SRB0039W.xml&dt=11

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享