多个供应商libc DNS分解器信息泄露漏洞

漏洞信息详情

多个供应商libc DNS分解器信息泄露漏洞

漏洞简介

The BIND 4版本和BIND 8.2.x版本的存根分解器函数库,以及例如glibc 2.2.5版本和之前版本、libc和libresolv的其他函数库在处理DNS回复时使用最大值缓冲区容量而不是实际容量,导致存根分解器越过实际边界读取(\”read buffer overflow\”),远程攻击者可以导致服务拒绝(崩溃)。

漏洞公告

Sun have released a security update to address this issue in the RAQ XTR. Please see references section for further details. A fix is linked below.
HP has released a revised advisory (HPSBUX0208-209(rev.15)) to address this issue in affected HP-UX systems. Customers who are affected by this issue are advised to apply appropriate patches. Further information regarding obtaining and applying patches is available in the referenced advisory.
HP has released an updated advisory HPSBUX0208-209(rev.14) for HP-UX systems. Preliminary updates for HP-UX 11 and 11.11 are available. Further information on obtaining and applying fixes is available in the referenced HP advisory (HPSBUX0208-209).
A security fix was provided on October 1st, 2002 for Openwall GNU/*/Linux. Users should contact the vendor to obtain fixed glibc packages.
Conectiva has released an advisory (CLA-2002:535) which contains upgrades. See the referenced advisory for further details on obtaining fixes.
NetBSD 1.6 is not affected by this issue. Users are strongly urged to upgrade their systems to NetBSD 1.6 or to update to the most recent sources of the appropriate branches. Further details are available in the referenced NetBSD advisory.
Red Hat has released an advisory (RHSA-2002:197-09). Updated glibc and nscd RPMs are available. See the attached advisory for details on obtaining fixes.
FreeBSD has released an advisory. Users are advised to upgrade vulnerable systems to the 4.7-STABLE branch, or to the appropriate RELENG_4_x branch after the correction date. A patch is also available. Further details may be found in the referenced advisory.
HP has released advisory HPSBUX0208-209 (rev.13) to address this issue.
Mandrake has released an advisory MDKSA-2004:009 to address this issue. Please see the referenced advisory for more information.
HP has released advisory HPSBTL0211-075 for HP Secure OS advising users to apply the fixes listed in Red Hat advisory RHSA-2002:197-09.
Fixes are available:
Sun Cobalt RaQ XTR

HP HP-UX 10.10

HP HP-UX 10.20

HP HP-UX 11.0

HP HP-UX 11.0 4

HP HP-UX 11.11

HP HP-UX 11.22

GNU glibc 2.1.3

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享