漏洞信息详情
dvips执行任意命令漏洞
- CNNVD编号:CNNVD-200210-313
- 危害等级: 高危
- CVE编号:
CVE-2002-0836
- 漏洞类型:
访问验证错误
- 发布时间:
2002-10-28
- 威胁类型:
远程
- 更新时间:
2005-05-13
- 厂 商:
redhat - 漏洞来源:
Discovery credited… -
漏洞简介
用于tetex包的Postscript文件中dvips转换器不安全调用system()函数。远程攻击者可以借助某些打印工作执行任意命令,其中可能包含打印字体。
漏洞公告
Red Hat has released RHSA-2002:195-10, which includes fixes to address this issue for Enterprise customers. Further details regarding obtaining and applying fixes are available in the referenced advisory.
RedHat has released RHSA-2002:194-18, which includes fixes. Further details are available in the advisory.
HP has released an advisory for HP Secure OS Software fo Linux. Users are adviced to upgrade using the fixes supplied in the RedHat advisory.
Mandrake has released MDKSA-2002:070, which includes fixes. Further details are available in the advisory.
Conectiva Linux has released a security advisory containing fixes. Further details are available in the advisory.
OpenPKG has released OpenPKG-SA-2002.015, which contains fix information. Further details about obtaining fixes are available in the referenced advisory.
Fixes:
teTeX teTeX 1.0.6
-
Debian libkpathsea-dev_1.0.7+20011202-7.1_alpha.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tetex-bin/libkpathsea-d
ev_1.0.7+20011202-7.1_alpha.deb -
Debian libkpathsea3_1.0.7+20011202-7.1_alpha.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tetex-bin/libkpathsea3_
1.0.7+20011202-7.1_alpha.deb -
Debian libkpathsea3_1.0.7+20011202-7.1_arm.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tetex-bin/libkpathsea3_
1.0.7+20011202-7.1_arm.deb -
Debian tetex-bin_1.0.6-7.3_alpha.debDebian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/t/tetex-bin/tetex-bin_1.0
.6-7.3_alpha.deb -
Debian tetex-bin_1.0.6-7.3_arm.debDebian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/t/tetex-bin/tetex-bin_1.0
.6-7.3_arm.deb -
Debian tetex-bin_1.0.6-7.3_i386.debDebian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/t/tetex-bin/tetex-bin_1.0
.6-7.3_i386.deb -
Debian tetex-bin_1.0.6-7.3_m68k.debDebian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/t/tetex-bin/tetex-bin_1.0
.6-7.3_m68k.deb -
Debian tetex-bin_1.0.6-7.3_powerpc.debDebian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/t/tetex-bin/tetex-bin_1.0
.6-7.3_powerpc.deb -
Debian tetex-bin_1.0.6-7.3_sparc.debDebian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/t/tetex-bin/tetex-bin_1.0
.6-7.3_sparc.deb -
Debian tetex-bin_1.0.7+20011202-7.1_alpha.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tetex-bin/tetex-bin_1.0
.7+20011202-7.1_alpha.deb -
Debian tetex-dev_1.0.6-7.3_alpha.debDebian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/t/tetex-bin/tetex-dev_1.0
.6-7.3_alpha.deb -
Debian tetex-dev_1.0.6-7.3_arm.debDebian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/t/tetex-bin/tetex-dev_1.0
.6-7.3_arm.deb -
Debian tetex-dev_1.0.6-7.3_i386.debDebian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/t/tetex-bin/tetex-dev_1.0
.6-7.3_i386.deb -
Debian tetex-dev_1.0.6-7.3_m68k.debDebian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/t/tetex-bin/tetex-dev_1.0
.6-7.3_m68k.deb -
Debian tetex-dev_1.0.6-7.3_powerpc.debDebian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/t/tetex-bin/tetex-dev_1.0
.6-7.3_powerpc.deb -
Debian tetex-dev_1.0.6-7.3_sparc.debDebian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/t/tetex-bin/tetex-dev_1.0
.6-7.3_sparc.deb -
Debian tetex-lib_1.0.6-7.3_alpha.debDebian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/t/tetex-bin/tetex-lib_1.0
.6-7.3_alpha.deb -
Debian tetex-lib_1.0.6-7.3_arm.debDebian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/t/tetex-bin/tetex-lib_1.0
.6-7.3_arm.deb -
Debian tetex-lib_1.0.6-7.3_i386.debDebian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/t/tetex-bin/tetex-lib_1.0
.6-7.3_i386.deb -
Debian tetex-lib_1.0.6-7.3_m68k.debDebian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/t/tetex-bin/tetex-lib_1.0
.6-7.3_m68k.deb -
Debian tetex-lib_1.0.6-7.3_powerpc.debDebian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/t/tetex-bin/tetex-lib_1.0
.6-7.3_powerpc.deb -
Debian tetex-lib_1.0.6-7.3_sparc.debDebian GNU/Linux 2.2 alias potato.
http://security.debian.org/pool/updates/main/t/tetex-bin/tetex-lib_1.0
.6-7.3_sparc.deb
teTeX teTeX 1.0.7
-
Debian libkpathsea-dev_1.0.7+20011202-7.1_alpha.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/t/tetex-bin/libkpathsea-d
ev_1.0.7+20011202-7.1_alpha.deb -
Debian libkpathsea-dev_1.0.7+20011202-7.1_arm.debDebian GNU/Linux 3.0 alias woody
参考网址
来源:US-CERT Vulnerability Note: VU#169841
名称: VU#169841
链接:http://www.kb.cert.org/vuls/id/169841来源: BID
名称: 5978
链接:http://www.securityfocus.com/bid/5978来源: REDHAT
名称: RHSA-2002:194
链接:http://www.redhat.com/support/errata/RHSA-2002-194.html来源: DEBIAN
名称: DSA-207
链接:http://www.debian.org/security/2002/dsa-207来源: BUGTRAQ
名称: 20021018 GLSA: tetex
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=103497852330838&w=2来源: XF
名称: dvips-system-execute-commands(10365)
链接:http://www.iss.net/security_center/static/10365.php来源: HP
名称: HPSBTL0210-073
链接:http://www.securityfocus.com/advisories/4567来源: REDHAT
名称: RHSA-2002:195
链接:http://www.redhat.com/support/errata/RHSA-2002-195.html来源: MANDRAKE
名称: MDKSA-2002:070
链接:http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-070.php来源: BUGTRAQ
名称: 20021216 [OpenPKG-SA-2002.015] OpenPKG Security Advisory (tetex)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=104005975415582&w=2来源: CONECTIVA
名称: CLA-2002:537
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000537