多个AFD工作目录本地缓冲区溢出漏洞

漏洞信息详情

多个AFD工作目录本地缓冲区溢出漏洞

漏洞简介

Automatic File Distributor (AFD) 1.2.14及其之前版本存在缓冲区溢出漏洞。本地用户借助超长MON_WORK_DIR环境变量或者(1)afd,(2) afdcmd,(3)afd_ctrl,(4)init_afd,(5)mafd,(6)mon_ctrl,(7)show_olog,或者(8)udc的-w (workdir)参数提升特权。

漏洞公告

The vendor has addressed this issue in AFD versions 1.2.15 and later. Those affected by this vulnerability are advised to upgrade.
AFD AFD 1.2

AFD AFD 1.2.1

AFD AFD 1.2.10

AFD AFD 1.2.11

AFD AFD 1.2.12

AFD AFD 1.2.13

AFD AFD 1.2.14

AFD AFD 1.2.2

AFD AFD 1.2.3

AFD AFD 1.2.4

AFD AFD 1.2.5

AFD AFD 1.2.6

AFD AFD 1.2.7

AFD AFD 1.2.8

AFD AFD 1.2.9

参考网址

来源: BID
名称: 5626
链接:http://www.securityfocus.com/bid/5626

来源: XF
名称: afd-multiple-binaries-bo(10036)
链接:http://www.iss.net/security_center/static/10036.php

来源: BUGTRAQ
名称: 20020904 AFD 1.2.14 multiple local root compromises
链接:http://archives.neohapsis.com/archives/bugtraq/2002-09/0029.html

来源: www.dwd.de
链接:http://www.dwd.de/AFD/txt/CHANGES

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享