漏洞信息详情
多个AFD工作目录本地缓冲区溢出漏洞
- CNNVD编号:CNNVD-200304-023
- 危害等级: 高危
- CVE编号:
CVE-2002-1503
- 漏洞类型:
缓冲区溢出
- 发布时间:
2003-04-02
- 威胁类型:
本地
- 更新时间:
2005-10-20
- 厂 商:
afd - 漏洞来源:
Discovery of this … -
漏洞简介
Automatic File Distributor (AFD) 1.2.14及其之前版本存在缓冲区溢出漏洞。本地用户借助超长MON_WORK_DIR环境变量或者(1)afd,(2) afdcmd,(3)afd_ctrl,(4)init_afd,(5)mafd,(6)mon_ctrl,(7)show_olog,或者(8)udc的-w (workdir)参数提升特权。
漏洞公告
The vendor has addressed this issue in AFD versions 1.2.15 and later. Those affected by this vulnerability are advised to upgrade.
AFD AFD 1.2
-
AFD src-1.2.15.tar.gz
http://www.dwd.de/AFD/download/src-1.2.15.tar.gz
AFD AFD 1.2.1
-
AFD src-1.2.15.tar.gz
http://www.dwd.de/AFD/download/src-1.2.15.tar.gz
AFD AFD 1.2.10
-
AFD src-1.2.15.tar.gz
http://www.dwd.de/AFD/download/src-1.2.15.tar.gz
AFD AFD 1.2.11
-
AFD src-1.2.15.tar.gz
http://www.dwd.de/AFD/download/src-1.2.15.tar.gz
AFD AFD 1.2.12
-
AFD src-1.2.15.tar.gz
http://www.dwd.de/AFD/download/src-1.2.15.tar.gz
AFD AFD 1.2.13
-
AFD src-1.2.15.tar.gz
http://www.dwd.de/AFD/download/src-1.2.15.tar.gz
AFD AFD 1.2.14
-
AFD patch-1.2.15.bz2Source code patch.
ftp://ftp.dwd.de/pub/afd/patch-1.2.15.bz2 -
AFD src-1.2.15.tar.gz
http://www.dwd.de/AFD/download/src-1.2.15.tar.gz
AFD AFD 1.2.2
-
AFD src-1.2.15.tar.gz
http://www.dwd.de/AFD/download/src-1.2.15.tar.gz
AFD AFD 1.2.3
-
AFD src-1.2.15.tar.gz
http://www.dwd.de/AFD/download/src-1.2.15.tar.gz
AFD AFD 1.2.4
-
AFD src-1.2.15.tar.gz
http://www.dwd.de/AFD/download/src-1.2.15.tar.gz
AFD AFD 1.2.5
-
AFD src-1.2.15.tar.gz
http://www.dwd.de/AFD/download/src-1.2.15.tar.gz
AFD AFD 1.2.6
-
AFD src-1.2.15.tar.gz
http://www.dwd.de/AFD/download/src-1.2.15.tar.gz
AFD AFD 1.2.7
-
AFD src-1.2.15.tar.gz
http://www.dwd.de/AFD/download/src-1.2.15.tar.gz
AFD AFD 1.2.8
-
AFD src-1.2.15.tar.gz
http://www.dwd.de/AFD/download/src-1.2.15.tar.gz
AFD AFD 1.2.9
-
AFD src-1.2.15.tar.gz
http://www.dwd.de/AFD/download/src-1.2.15.tar.gz
参考网址
来源: BID
名称: 5626
链接:http://www.securityfocus.com/bid/5626
来源: XF
名称: afd-multiple-binaries-bo(10036)
链接:http://www.iss.net/security_center/static/10036.php
来源: BUGTRAQ
名称: 20020904 AFD 1.2.14 multiple local root compromises
链接:http://archives.neohapsis.com/archives/bugtraq/2002-09/0029.html
来源: www.dwd.de
链接:http://www.dwd.de/AFD/txt/CHANGES