Linuxconf本地环境变量缓冲区溢出漏洞。

漏洞信息详情

Linuxconf本地环境变量缓冲区溢出漏洞。

漏洞简介

Linuxconf 1.28r4之前版本存在缓冲区溢出漏洞。本地用户借助超长环境变量执行任意代码。该漏洞溢出一个已产生的错误字符串。

漏洞公告

The vendor has released a fix which addresses this issue:
Jacques Gelinas Linuxconf 1.1.6 r10

Jacques Gelinas Linuxconf 1.1.7

Jacques Gelinas Linuxconf 1.1.8

Jacques Gelinas Linuxconf 1.1.9 r2

Jacques Gelinas Linuxconf 1.1.9 r1

Jacques Gelinas Linuxconf 1.2 r1

Jacques Gelinas Linuxconf 1.2 r2

Jacques Gelinas Linuxconf 1.2

Jacques Gelinas Linuxconf 1.2.1 r3

Jacques Gelinas Linuxconf 1.2.1 r1

Jacques Gelinas Linuxconf 1.2.1 r2

Jacques Gelinas Linuxconf 1.2.1 r5

Jacques Gelinas Linuxconf 1.2.1 r7

Jacques Gelinas Linuxconf 1.2.1 r8

Jacques Gelinas Linuxconf 1.2.1 r6

Jacques Gelinas Linuxconf 1.2.1

Jacques Gelinas Linuxconf 1.2.1 r4

Jacques Gelinas Linuxconf 1.2.2

Jacques Gelinas Linuxconf 1.2.3 r1

Jacques Gelinas Linuxconf 1.2.3

Jacques Gelinas Linuxconf 1.2.3 r2

Jacques Gelinas Linuxconf 1.2.4 r2

Jacques Gelinas Linuxconf 1.2.4

Jacques Gelinas Linuxconf 1.2.4 r5

Jacques Gelinas Linuxconf 1.2.4 r4

Jacques Gelinas Linuxconf 1.27 r3

Jacques Gelinas Linuxconf 1.27

Jacques Gelinas Linuxconf 1.27 r5

Jacques Gelinas Linuxconf 1.27 r4

Jacques Gelinas Linuxconf 1.28 r3

Jacques Gelinas Linuxconf 1.28 r2

Jacques Gelinas Linuxconf 1.28

Jacques Gelinas Linuxconf 1.28 r1

参考网址

来源: BID
名称: 5585
链接:http://www.securityfocus.com/bid/5585

来源: XF
名称: linuxconf-linuxconflang-env-bo(9980)
链接:http://www.iss.net/security_center/static/9980.php

来源: BUGTRAQ
名称: 20020828 iDEFENSE Security Advisory: Linuxconf locally exploitable buffer overflow
链接:http://archives.neohapsis.com/archives/bugtraq/2002-08/0304.html

来源: VULNWATCH
名称: 20020828 iDEFENSE Security Advisory: Linuxconf locally exploitable buffer overflow
链接:http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0093.html

来源: www.solucorp.qc.ca
链接:http://www.solucorp.qc.ca/changes.hc?projet=linuxconf&version=1.28r4

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享