漏洞信息详情
GTKHTML Malformed HTML文件服务拒绝漏洞
- CNNVD编号:CNNVD-200305-010
- 危害等级: 中危
- CVE编号:
CVE-2003-0133
- 漏洞类型:
其他
- 发布时间:
2003-05-05
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
gnome - 漏洞来源:
Discovery of this … -
漏洞简介
包含在Evolution 1.2.4之前版本的GtkHTML存在漏洞。远程攻击者可以借助某个畸形消息导致服务拒绝(崩溃)。
漏洞公告
This issue has been addressed in the GtkHTML component that is included in Evolution 1.2.4. Evolution users are advised to upgrade.
Red Hat has released a security advisory (RHSA-2003:264-01) that states the previous security advisory (RHSA-2003:126-06) as obsolete. New fixes have been made available in this advisory and users are advised to upgrade as soon as possible.
Conectiva has released a security advisory (CLSA-2003:737) containing fixes to address this issue.
Mandrake has released a security advisory (MDKSA-2003:093) containing updated fixes to address this issue.
Debian Linux has released advisory DSA 710-1 addressing this issue. Please see the referenced advisory for details on obtaining and applying fixes.
Fixes are available:
GNOME GtkHTML 1.0.1
-
Conectiva gtkhtml-1.0.1-1U70_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/gtkhtml-1.0.1-1U70_2cl.i3
86.rpm -
Conectiva gtkhtml-1.0.1-4U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/gtkhtml-1.0.1-4U80_2cl.i386
.rpm -
Conectiva gtkhtml-devel-1.0.1-1U70_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/gtkhtml-devel-1.0.1-1U70_
2cl.i386.rpm -
Conectiva gtkhtml-devel-1.0.1-4U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/gtkhtml-devel-1.0.1-4U80_2c
l.i386.rpm -
Conectiva gtkhtml-devel-static-1.0.1-1U70_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/gtkhtml-devel-static-1.0.
1-1U70_2cl.i386.rpm -
Conectiva gtkhtml-devel-static-1.0.1-4U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/gtkhtml-devel-static-1.0.1-
4U80_2cl.i386.rpm -
Conectiva libgtkhtml-i18n-1.0.1-4U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/libgtkhtml-i18n-1.0.1-4U80_
2cl.i386.rpm -
Conectiva libgtkhtml20-1.0.1-4U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/libgtkhtml20-1.0.1-4U80_2cl
.i386.rpm
GNOME GtkHTML 1.0.2
-
Debian gtkhtml_1.0.2-1.woody1_alpha.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/gtkhtml/gtkhtml_1.0.2-1
.woody1_alpha.deb -
Debian gtkhtml_1.0.2-1.woody1_arm.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/gtkhtml/gtkhtml_1.0.2-1
.woody1_arm.deb -
Debian gtkhtml_1.0.2-1.woody1_hppa.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/gtkhtml/gtkhtml_1.0.2-1
.woody1_hppa.deb -
Debian gtkhtml_1.0.2-1.woody1_i386.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/gtkhtml/gtkhtml_1.0.2-1
.woody1_i386.deb -
Debian gtkhtml_1.0.2-1.woody1_ia64.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/gtkhtml/gtkhtml_1.0.2-1
.woody1_ia64.deb -
Debian gtkhtml_1.0.2-1.woody1_m68k.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/gtkhtml/gtkhtml_1.0.2-1
.woody1_m68k.deb -
Debian gtkhtml_1.0.2-1.woody1_mips.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/gtkhtml/gtkhtml_1.0.2-1
.woody1_mips.deb -
Debian gtkhtml_1.0.2-1.woody1_mipsel.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/gtkhtml/gtkhtml_1.0.2-1
.woody1_mipsel.deb -
Debian gtkhtml_1.0.2-1.woody1_powerpc.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/gtkhtml/gtkhtml_1.0.2-1
.woody1_powerpc.deb -
Debian gtkhtml_1.0.2-1.woody1_s390.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/gtkhtml/gtkhtml_1.0.2-1
.woody1_s390.deb -
Debian gtkhtml_1.0.2-1.woody1_sparc.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/gtkhtml/gtkhtml_1.0.2-1
.woody1_sparc.deb -
Debian libgtkhtml-data_1.0.2-1.woody1_all.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/gtkhtml/libgtkhtml-data
_1.0.2-1.woody1_all.deb -
Debian libgtkhtml-dev_1.0.2-1.woody1_alpha.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/gtkhtml/libgtkhtml-dev_
1.0.2-1.woody1_alpha.deb -
Debian libgtkhtml-dev_1.0.2-1.woody1_arm.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/gtkhtml/libgtkhtml-dev_
1.0.2-1.woody1_arm.deb -
Debian libgtkhtml-dev_1.0.2-1.woody1_hppa.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/gtkhtml/libgtkhtml-dev_
1.0.2-1.woody1_hppa.deb -
Debian libgtkhtml-dev_1.0.2-1.woody1_i386.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/gtkhtml/libgtkhtml-dev_
1.0.2-1.woody1_i386.deb -
Debian libgtkhtml-dev_1.0.2-1.woody1_ia64.debDebian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/gtkhtml/libgtkhtml-dev_
1.0.2-1.woody1_ia64.deb - Debian libgtkhtml-dev_1.0.2-1.woody1_m68k.
参考网址
来源: REDHAT
名称: RHSA-2003:126
链接:http://www.redhat.com/support/errata/RHSA-2003-126.html
来源: MANDRAKE
名称: MDKSA-2003:046
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2003:046
来源: CONECTIVA
名称: CLA-2003:737
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000737
来源: US Government Resource: oval:org.mitre.oval:def:138
名称: oval:org.mitre.oval:def:138
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:138