漏洞信息详情
Netris客户端缓冲区溢出漏洞
- CNNVD编号:CNNVD-200308-144
- 危害等级: 高危
- CVE编号:
CVE-2003-0685
- 漏洞类型:
缓冲区溢出
- 发布时间:
2003-08-27
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
netris - 漏洞来源:
The discovery of t… -
漏洞简介
Netris 0.52及其早期版本和可能其他版本存在缓冲区溢出漏洞。远程恶意Netris服务器可以借助超长服务器响应执行netris客户端的任意代码。
漏洞公告
Debian has released an advisory (DSA 372-1) that addresses this issue. Please see the attached advisory for details on obtaining and applying fixes.
This vulnerability has been addressed in Netris 0.52.
Netris Netris 0.3
-
Netris netris-0.52.tar.gz
ftp://ftp.netris.org/pub/netris/netris-0.52.tar.gz
Netris Netris 0.4
-
Netris netris-0.52.tar.gz
ftp://ftp.netris.org/pub/netris/netris-0.52.tar.gz
Netris Netris 0.5
-
Debian netris_0.5-4woody1_alpha.debDebian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/netris/netris_0.5-4wood
y1_alpha.deb -
Debian netris_0.5-4woody1_arm.debDebian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/netris/netris_0.5-4wood
y1_arm.deb -
Debian netris_0.5-4woody1_hppa.debDebian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/netris/netris_0.5-4wood
y1_hppa.deb -
Debian netris_0.5-4woody1_i386.debDebian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/netris/netris_0.5-4wood
y1_i386.deb -
Debian netris_0.5-4woody1_ia64.debDebian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/netris/netris_0.5-4wood
y1_ia64.deb -
Debian netris_0.5-4woody1_m68k.debDebian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/netris/netris_0.5-4wood
y1_m68k.deb -
Debian netris_0.5-4woody1_mips.debDebian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/netris/netris_0.5-4wood
y1_mips.deb -
Debian netris_0.5-4woody1_mipsel.debDebian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/netris/netris_0.5-4wood
y1_mipsel.deb -
Debian netris_0.5-4woody1_powerpc.debDebian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/netris/netris_0.5-4wood
y1_powerpc.deb -
Debian netris_0.5-4woody1_s390.debDebian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/netris/netris_0.5-4wood
y1_s390.deb -
Debian netris_0.5-4woody1_sparc.debDebian GNU/Linux 3.0 alias woody.
http://security.debian.org/pool/updates/main/n/netris/netris_0.5-4wood
y1_sparc.deb -
Netris netris-0.5-0.52.diff
ftp://ftp.netris.org/pub/netris/netris-0.5-0.52.diff -
Netris netris-0.52.tar.gz
ftp://ftp.netris.org/pub/netris/netris-0.52.tar.gz
参考网址
来源: DEBIAN
名称: DSA-372
链接:http://www.debian.org/security/2003/dsa-372
来源: BUGTRAQ
名称: 20030812 Netris client Buffer Overflow Vulnerability.
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=106071059430211&w=2
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END