GNU CFEngine AuthenticationDialogue基于远程堆缓冲区溢出漏洞 GNU CFEngine AuthenticationDialogue远程基于堆缓冲区溢出漏洞

漏洞信息详情

GNU CFEngine AuthenticationDialogue基于远程堆缓冲区溢出漏洞
GNU CFEngine AuthenticationDialogue远程基于堆缓冲区溢出漏洞

漏洞简介

Cfengine 2.0.0到2.1.7p1版本cfservd 中的AuthenticationDialogue函数存在基于堆的缓冲区溢出漏洞。远程攻击者可以通过RSA认证期间的超长SAUTH命令执行任意代码。

漏洞公告

Gentoo has released an advisory to provide updates. Updates may be applied with the following commands:
emerge sync
emerge -pv “>=net-misc/cfengine-2.1.8”
emerge “>=net-misc/cfengine-2.1.8”
The vendor has released an update to address this issue:
GNU Cfengine 2.0 .0

GNU Cfengine 2.0 .8

GNU Cfengine 2.0 .8p1

GNU Cfengine 2.0.1

GNU Cfengine 2.0.2

GNU Cfengine 2.0.3

GNU Cfengine 2.0.4

GNU Cfengine 2.0.5

GNU Cfengine 2.0.5 b1

GNU Cfengine 2.0.5 pre2

GNU Cfengine 2.0.5 pre

GNU Cfengine 2.0.6

GNU Cfengine 2.0.7

GNU Cfengine 2.0.7 p1

GNU Cfengine 2.0.7 p3

GNU Cfengine 2.0.7 p2

GNU Cfengine 2.1 .0a8

GNU Cfengine 2.1 .0a9

GNU Cfengine 2.1 .0a6

GNU Cfengine 2.1.7 p1

参考网址

来源: XF
名称: cfengine-cfservd-command-execution(16935)
链接:http://xforce.iss.net/xforce/xfdb/16935

来源: BID
名称: 10899
链接:http://www.securityfocus.com/bid/10899

来源: www.coresecurity.com
链接:http://www.coresecurity.com/common/showdoc.php?idx=387&idxseccion=10

来源: GENTOO
名称: GLSA-200408-08
链接:http://security.gentoo.org/glsa/glsa-200408-08.xml

来源: SECUNIA
名称: 12251
链接:http://secunia.com/advisories/12251

来源: BUGTRAQ
名称: 20050219 cfengine rsa heap remote exploit: part of PTjob project
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=110886670528775&w=2

来源: BUGTRAQ
名称: 20040809 CORE-2004-0714: Cfengine RSA Authentication Heap Corruption
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=109208394910086&w=2

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享