GTKHTML Malformed HTML文件服务拒绝漏洞

漏洞信息详情

GTKHTML Malformed HTML文件服务拒绝漏洞

漏洞简介

用于Evolution的gtkhtml 1.1.10之前版本存在漏洞。远程攻击者可以借助畸形消息导致服务拒绝(崩溃),该信息导致空指针引用。

漏洞公告

This issue has been addressed in the GtkHTML component that is included in Evolution 1.2.4. Evolution users are advised to upgrade.
Red Hat has released a security advisory (RHSA-2003:264-01) that states the previous security advisory (RHSA-2003:126-06) as obsolete. New fixes have been made available in this advisory and users are advised to upgrade as soon as possible.
Conectiva has released a security advisory (CLSA-2003:737) containing fixes to address this issue.
Mandrake has released a security advisory (MDKSA-2003:093) containing updated fixes to address this issue.
Debian Linux has released advisory DSA 710-1 addressing this issue. Please see the referenced advisory for details on obtaining and applying fixes.
Fixes are available:
GNOME GtkHTML 1.0.1

GNOME GtkHTML 1.0.2

参考网址

来源: REDHAT
名称: RHSA-2003:264
链接:http://www.redhat.com/support/errata/RHSA-2003-264.html

来源: DEBIAN
名称: DSA-710
链接:http://www.debian.org/security/2005/dsa-710

来源: MANDRAKE
名称: MDKSA-2003:093
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2003:093

来源: CONECTIVA
名称: CLA-2003:737
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000737

来源: US Government Resource: oval:org.mitre.oval:def:148
名称: oval:org.mitre.oval:def:148
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:148

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享