漏洞信息详情
XFree86多个未明整数溢出漏洞
- CNNVD编号:CNNVD-200310-028
- 危害等级: 高危
- CVE编号:
CVE-2003-0730
- 漏洞类型:
缓冲区溢出
- 发布时间:
2003-10-20
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
netbsd - 漏洞来源:
The discovery of t… -
漏洞简介
XFree86 4.3.0版本的字体库存在多个整数溢出漏洞。本地或者远程攻击者借助基于堆和基于栈的缓冲区溢出攻击导致服务拒绝或者执行任意代码。
漏洞公告
Reportedly, this issue has been addressed in the current XFree86 CVS tree, but Symantec has not confirmed this.
Please see the referenced advisories for more information.
RedHat XFree86-ISO8859-9-75dpi-fonts-4.2.0-72.i386.rpm
-
RedHat XFree86-ISO8859-9-75dpi-fonts-4.2.1-23.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/XFree86-ISO8859-9-75dpi-fonts-
4.2.1-23.i386.rpm
RedHat XFree86-100dpi-fonts-4.0.3-5.i386.rpm
-
RedHat XFree86-100dpi-fonts-4.1.0-50.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/XFree86-100dpi-fonts-4.1.0-50.
i386.rpm
RedHat XFree86-Xnest-4.2.0-72.i386.rpm
-
RedHat XFree86-Xnest-4.2.1-23.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/XFree86-Xnest-4.2.1-23.i386.rp
m
RedHat XFree86-base-fonts-4.2.0-8.i386.rpm
-
RedHat XFree86-base-fonts-4.2.1-13.73.23.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/XFree86-base-fonts-4.2.1-13.73
.23.i386.rpm
RedHat XFree86-ISO8859-9-100dpi-fonts-4.2.0-8.i386.rpm
-
RedHat XFree86-ISO8859-9-100dpi-fonts-4.2.1-13.73.23.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/XFree86-ISO8859-9-100dpi-fonts
-4.2.1-13.73.23.i386.rpm
RedHat XFree86-Xnest-4.1.0-3.i386.rpm
-
RedHat XFree86-Xnest-4.1.0-50.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/XFree86-Xnest-4.1.0-50.i386.rp
m
RedHat XFree86-ISO8859-15-75dpi-fonts-4.1.0-3.ia64.rpm
-
RedHat XFree86-ISO8859-15-75dpi-fonts-4.1.0-50.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/XFree86-ISO8859-15-75dpi-fonts
-4.1.0-50.ia64.rpm
RedHat XFree86-75dpi-fonts-4.1.0-3.i386.rpm
-
RedHat XFree86-75dpi-fonts-4.1.0-50.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/XFree86-75dpi-fonts-4.1.0-50.i
386.rpm
RedHat XFree86-Xnest-4.1.0-3.ia64.rpm
-
RedHat XFree86-Xnest-4.1.0-50.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/XFree86-Xnest-4.1.0-50.ia64.rp
m
RedHat XFree86-xfs-4.2.0-8.i386.rpm
-
RedHat XFree86-xfs-4.2.1-13.73.23.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/XFree86-xfs-4.2.1-13.73.23.i38
6.rpm
Sun Solaris 8
-
Sun 109862-04
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21
-109862-04-1 -
Sun 119067-06
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21
-119067-06-1
RedHat XFree86-100dpi-fonts-4.2.0-72.i386.rpm
-
RedHat XFree86-100dpi-fonts-4.2.1-23.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/XFree86-100dpi-fonts-4.2.1-23.
i386.rpm
RedHat XFree86-twm-4.0.3-5.i386.rpm
-
RedHat XFree86-twm-4.1.0-50.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/XFree86-twm-4.1.0-50.i386.rpm
RedHat XFree86-font-utils-4.2.0-72.i386.rpm
-
RedHat XFree86-font-utils-4.2.1-23.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/XFree86-font-utils-4.2.1-23.i3
86.rpm
RedHat XFree86-ISO8859-2-75dpi-fonts-4.1.0-3.i386.rpm
-
RedHat XFree86-ISO8859-2-75dpi-fonts-4.1.0-50.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/XFree86-ISO8859-2-75dpi-fonts-
4.1.0-50.i386.rpm
RedHat XFree86-Xnest-4.2.0-8.i386.rpm
-
RedHat XFree86-Xnest-4.2.1-13.73.23.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/XFree86-Xnest-4.2.1-13.73.23.i
386.rpm
RedHat XFree86-ISO8859-2-75dpi-fonts-4.2.0-72.i386.rpm
-
RedHat XFree86-ISO8859-2-75dpi-fonts-4.2.1-23.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/XFree86-ISO8859-2-75dpi-fonts-
4.2.1-23.i386.rpm
RedHat XFree86-ISO8859-9-75dpi-fonts-2.1.2-16.noarch.rpm
-
RedHat XFree86-ISO8859-9-75dpi-fonts-4.1.0-50.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/XFree86-ISO8859-9-75dpi-fonts-
4.1.0-50.i386.rpm
RedHat XFree86-100dpi-fonts-4.1.0-3.ia64.rpm
-
RedHat XFree86-100dpi-fonts-4.1.0-50.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/XFree86-100dpi-fonts-4.1.0-50.
ia64.rpm
RedHat XFree86-ISO8859-15-75dpi-fonts-4.1.0-3.i386.rpm
-
RedHat XFree86-ISO8859-15-75dpi-fonts-4.1.0-50.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/XFree86-ISO8859-15-75dpi-fonts
-4.1.0-50.i386.rpm
RedHat XFree86-libs-4.1.0-3.i386.rpm
-
RedHat XFree86-libs-4.1.0-50.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/XFree86-libs-4.1.0-50.i386.rpm
RedHat XFree86-ISO8859-9-100dpi-fonts-4.1.0-3.i386.rpm
-
RedHat XFree86-ISO8859-9-100dpi-fonts-4.1.0-50.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/XFree86-ISO8859-9-100dpi-fonts
-4.1.0-50.i386.rpm
RedHat XFree86-libs-4.0.3-5.i386.rpm
-
RedHat XFree86-libs-4.1.0-50.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/XFree86-libs-4.1.0-50.i386.rpm
RedHat XFree86-Xvfb-4.0.3-5.i386.rpm
-
RedHat XFree86-Xvfb-4.1.0-50.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/XFree86-Xvfb-4.1.0-50.i386.
参考网址
来源: BID
名称: 8514
链接:http://www.securityfocus.com/bid/8514
来源: REDHAT
名称: RHSA-2003:286
链接:http://www.redhat.com/support/errata/RHSA-2003-286.html
来源: DEBIAN
名称: DSA-380
链接:http://www.debian.org/security/2003/dsa-380
来源: BUGTRAQ
名称: 20030830 Multiple integer overflows in XFree86 (local/remote)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=106229335312429&w=2
来源: REDHAT
名称: RHSA-2003:289
链接:http://www.redhat.com/support/errata/RHSA-2003-289.html
来源: REDHAT
名称: RHSA-2003:288
链接:http://www.redhat.com/support/errata/RHSA-2003-288.html
来源: SGI
名称: 20031101-01-U
链接:ftp://patches.sgi.com/support/free/security/advisories/20031101-01-U.asc
来源: NETBSD
名称: NetBSD-SA2003-015
链接:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-015.txt.asc
来源: REDHAT
名称: RHSA-2003:287
链接:http://www.redhat.com/support/errata/RHSA-2003-287.html
来源: MANDRAKE
名称: MDKSA-2003:089
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2003:089
来源: VUPEN
名称: ADV-2007-0589
链接:http://www.frsirt.com/english/advisories/2007/0589
来源: support.avaya.com
链接:http://support.avaya.com/elmodocs2/security/ASA-2007-074.htm
来源: SUNALERT
名称: 102803
链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-102803-1
来源: SECUNIA
名称: 24247
链接:http://secunia.com/advisories/24247
来源: SECUNIA
名称: 24168
链接:http://secunia.com/advisories/24168
来源: CONECTIVA
名称: CLA-2004:821
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000821