漏洞信息详情
Xine Bug Reporting Script不安全文件创建漏洞
- CNNVD编号:CNNVD-200404-037
- 危害等级: 低危
- CVE编号:
CVE-2004-0372
- 漏洞类型:
设计错误
- 发布时间:
2004-04-15
- 威胁类型:
本地
- 更新时间:
2005-10-20
- 厂 商:
xine - 漏洞来源:
Discovery is credi… -
漏洞简介
xine 存在漏洞。本地用户可以通过报告错误电子邮件上的链接攻击覆盖任意文件,该邮件是由(1) xine-bugreport 或(2) xine-check 脚本生成。
漏洞公告
Updates are available. Please see the referenced advisories for more information.
xine xine-ui 0.9.22
-
Mandrake xine-ui-0.9.22-5.1.92mdk.amd64.rpmMandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-ui-0.9.22-5.1.92mdk.i586.rpmMandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-ui-aa-0.9.22-5.1.92mdk.amd64.rpmMandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-ui-aa-0.9.22-5.1.92mdk.i586.rpmMandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-ui-fb-0.9.22-5.1.92mdk.amd64.rpmMandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-ui-fb-0.9.22-5.1.92mdk.i586.rpmMandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php
xine xine-ui 0.9.23
-
Mandrake xine-ui-0.9.23-3.1.100mdk.i586.rpmMandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-ui-aa-0.9.23-3.1.100mdk.i586.rpmMandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xine-ui-fb-0.9.23-3.1.100mdk.i586.rpmMandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php
xine xine 0.9.8
-
Debian xine-ui_0.9.8-5.1_alpha.debDebian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.9.8-5
.1_alpha.deb -
Debian xine-ui_0.9.8-5.1_arm.debDebian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.9.8-5
.1_arm.deb -
Debian xine-ui_0.9.8-5.1_hppa.debDebian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.9.8-5
.1_hppa.deb -
Debian xine-ui_0.9.8-5.1_i386.debDebian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.9.8-5
.1_i386.deb -
Debian xine-ui_0.9.8-5.1_ia64.debDebian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.9.8-5
.1_ia64.deb -
Debian xine-ui_0.9.8-5.1_m68k.debDebian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.9.8-5
.1_m68k.deb -
Debian xine-ui_0.9.8-5.1_mips.debDebian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.9.8-5
.1_mips.deb -
Debian xine-ui_0.9.8-5.1_mipsel.debDebian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.9.8-5
.1_mipsel.deb -
Debian xine-ui_0.9.8-5.1_powerpc.debDebian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.9.8-5
.1_powerpc.deb -
Debian xine-ui_0.9.8-5.1_s390.debDebian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.9.8-5
.1_s390.deb -
Debian xine-ui_0.9.8-5.1_sparc.debDebian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xine-ui/xine-ui_0.9.8-5
.1_sparc.deb -
Fedora Legacy xine-0.9.8-4.2.legacy.i386.rpmRed Hat Linux 7.3:
http://download.fedoralegacy.org/redhat/7.3/updates/i386/xine-0.9.8-4.
2.legacy.i386.rpm -
Fedora Legacy xine-devel-0.9.8-4.2.legacy.i386.rpmRed Hat Linux 7.3:
http://download.fedoralegacy.org/redhat/7.3/updates/i386/xine-devel-0.
9.8-4.2.legacy.i386.rpm
参考网址
来源: XF
名称: xine-xinebugreport-xinecheck-symlink(15564)
链接:http://xforce.iss.net/xforce/xfdb/15564
来源: DEBIAN
名称: DSA-477
链接:http://www.debian.org/security/2004/dsa-477
来源: BID
名称: 9939
链接:http://www.securityfocus.com/bid/9939
来源: GENTOO
名称: GLSA-200404-20
链接:http://security.gentoo.org/glsa/glsa-200404-20.xml
来源: BUGTRAQ
名称: 20040320 xine-check/xine-bugreport symlink vulnerability.
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=107997911025558&w=2
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END