漏洞信息详情
Traceroute-Nanog主机名缓冲区溢出漏洞
- CNNVD编号:CNNVD-200301-001
- 危害等级: 中危
- CVE编号:
CVE-2002-1386
- 漏洞类型:
缓冲区溢出
- 发布时间:
2003-01-02
- 威胁类型:
本地
- 更新时间:
2005-10-20
- 厂 商:
ehud_gavron - 漏洞来源:
Vulnerability disc… -
漏洞简介
traceroute-nanog (也称为traceroute-ng)存在缓冲区溢出漏洞。本地用户可以借助超长主机名参数执行任意代码。
漏洞公告
This problem has reportedly been fixed in packages supplied by SuSE in SuSE Security Advisory SuSE-SA:2002:043. This information is unconfirmed.
Fixes available:
Ehud Gavron TrACESroute 6.0
-
Debian traceroute-nanog_6.0-2.2_alpha.deb
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer
oute-nanog_6.0-2.2_alpha.deb -
Debian traceroute-nanog_6.0-2.2_arm.deb
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer
oute-nanog_6.0-2.2_arm.deb -
Debian traceroute-nanog_6.0-2.2_i386.deb
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer
oute-nanog_6.0-2.2_i386.deb -
Debian traceroute-nanog_6.0-2.2_m68k.deb
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer
oute-nanog_6.0-2.2_m68k.deb -
Debian traceroute-nanog_6.0-2.2_powerpc.deb
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer
oute-nanog_6.0-2.2_powerpc.deb -
Debian traceroute-nanog_6.0-2.2_sparc.deb
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer
oute-nanog_6.0-2.2_sparc.deb -
SuSE nkitb-2002.11.6-0.alpha.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.0/a1/nkitb-2002.11.6-0.alpha.
rpm -
SuSE nkitb-2002.11.6-0.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.0/a1/nkitb-2002.11.6-0.i386.
rpm -
SuSE nkitb-2002.11.6-0.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.0/a1/nkitb-2002.11.6-0.ppc.rp
m -
SuSE traceroute-6.0-0.alpha.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.1/n1/traceroute-6.0-0.alpha.r
pm -
SuSE traceroute-6.0-0.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.1/n1/traceroute-6.0-0.i386.r
pm -
SuSE traceroute-6.0-0.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/n1/traceroute-6.0-0.ppc.rpm
Ehud Gavron TrACESroute 6.1.1
-
Debian traceroute-nanog_6.1.1-1.2_alpha.deb
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer
oute-nanog_6.1.1-1.2_alpha.deb -
Debian traceroute-nanog_6.1.1-1.2_arm.deb
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer
oute-nanog_6.1.1-1.2_arm.deb -
Debian traceroute-nanog_6.1.1-1.2_hppa.deb
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer
oute-nanog_6.1.1-1.2_hppa.deb -
Debian traceroute-nanog_6.1.1-1.2_i386.deb
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer
oute-nanog_6.1.1-1.2_i386.deb -
Debian traceroute-nanog_6.1.1-1.2_ia64.deb
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer
oute-nanog_6.1.1-1.2_ia64.deb -
Debian traceroute-nanog_6.1.1-1.2_m68k.deb
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer
oute-nanog_6.1.1-1.2_m68k.deb -
Debian traceroute-nanog_6.1.1-1.2_mips.deb
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer
oute-nanog_6.1.1-1.2_mips.deb -
Debian traceroute-nanog_6.1.1-1.2_mipsel.deb
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer
oute-nanog_6.1.1-1.2_mipsel.deb -
Debian traceroute-nanog_6.1.1-1.2_powerpc.deb
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer
oute-nanog_6.1.1-1.2_powerpc.deb -
Debian traceroute-nanog_6.1.1-1.2_s390.deb
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer
oute-nanog_6.1.1-1.2_s390.deb -
Debian traceroute-nanog_6.1.1-1.2_sparc.deb
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer
oute-nanog_6.1.1-1.2_sparc.deb -
SuSE traceroute-6.1.1-0.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n1/traceroute-6.1.1-0.i386
.rpm -
SuSE traceroute-6.1.1-0.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.3/n1/traceroute-6.1.1-0.i386
.rpm -
SuSE traceroute-6.1.1-0.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/n1/traceroute-6.1.1-0.i386
.rpm -
SuSE traceroute-6.1.1-0.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/n1/traceroute-6.1.1-0.ppc.r
pm -
SuSE traceroute-6.1.1-0.sparc.rpm
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/n1/traceroute-6.1.1-0.spa
rc.rpm
参考网址
来源: BID
名称: 6274
链接:http://www.securityfocus.com/bid/6274
来源: XF
名称: traceroute-nanog-bo(10608)
链接:http://www.iss.net/security_center/static/10608.php
来源: DEBIAN
名称: DSA-254
链接:http://www.debian.org/security/2003/dsa-254
来源: BUGTRAQ
名称: 20021128 TracerouteNG – never ending story
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=103849968732634&w=2
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END