Midnight Commander多个未明安全漏洞

漏洞信息详情

Midnight Commander多个未明安全漏洞

漏洞简介

Midnight Commander是一款强大的GNU/LINUX系统的文件管理器。
Midnight Commander存在多个未明漏洞,远程攻击者可以利用这些漏洞进行缓冲区溢出,进行符号连接攻击及拒绝服务等攻击。
Midnight Commander存在缓冲区溢出,不安全建立文件和目录及格式串问题,目前没有详细漏洞细节提供。

漏洞公告

厂商补丁:
Debian
——

http://www.debian.org/security/2004/dsa-497

MandrakeSoft
————
MandrakeSoft已经为此发布了一个安全公告(MDKSA-2004:039)以及相应补丁:

MDKSA-2004:039:Updated mc packages fix vulnerabilities

链接:http://www.linux-mandrake.com/en/security/2004/2004-039.php” target=”_blank”>
http://www.linux-mandrake.com/en/security/2004/2004-039.php

补丁下载:

Updated Packages:

Mandrakelinux 10.0:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/RPMS/mc-4.6.0-6.1.100mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/SRPMS/mc-4.6.0-6.1.100mdk.src.rpm

Corporate Server 2.1:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/mc-4.6.0-4.2.C21mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/SRPMS/mc-4.6.0-4.2.C21mdk.src.rpm

Corporate Server 2.1/x86_64:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/x86_64/corporate/2.1/RPMS/mc-4.6.0-4.2.C21mdk.x86_64.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/x86_64/corporate/2.1/SRPMS/mc-4.6.0-4.2.C21mdk.src.rpm

Mandrakelinux 9.1:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/RPMS/mc-4.6.0-4.2.91mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/SRPMS/mc-4.6.0-4.2.91mdk.src.rpm

Mandrakelinux 9.1/PPC:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/RPMS/mc-4.6.0-4.2.91mdk.ppc.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/SRPMS/mc-4.6.0-4.2.91mdk.src.rpm

Mandrakelinux 9.2:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.2/RPMS/mc-4.6.0-4.2.92mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.2/SRPMS/mc-4.6.0-4.2.92mdk.src.rpm

Mandrakelinux 9.2/AMD64:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/amd64/9.2/RPMS/mc-4.6.0-4.2.92mdk.amd64.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/amd64/9.2/SRPMS/mc-4.6.0-4.2.92mdk.src.rpm

上述升级软件还可以在下列地址中的任意一个镜像ftp服务器上下载:

http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php
RedHat
——
RedHat已经为此发布了一个安全公告(RHSA-2004:173-00)以及相应补丁:

RHSA-2004:173-00:Updated mc packages resolve several vulnerabilities

链接:https://www.redhat.com/support/errata/RHSA-2004-173.html” target=”_blank”>https://www.redhat.com/support/errata/RHSA-2004-173.html

补丁下载:

Fedora Upgrade mc-4.6.0-14.10.i386.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386/mc-4.6.0-14.10.i386.rpm” target=”_blank”>
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386/mc-4.6.0-14.10.i386.rpm

Fedora Upgrade mc-debuginfo-4.6.0-14.10.i386.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386/debug/mc-debuginfo-4.6.0-14.10.i386.rpm” target=”_blank”>
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386/debug/mc-debuginfo-4.6.0-14.10.i386.rpm

Fedora Upgrade mc-4.6.0-14.10.x86_64.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/x86_64/mc-4.6.0-14.10.x86_64.rpm” target=”_blank”>
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/x86_64/mc-4.6.0-14.10.x86_64.rpm

Fedora Upgrade mc-debuginfo-4.6.0-14.10.x86_64.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/x86_64/debug/mc-debuginfo-4.6.0-14.10.x86_64.rpm” target=”_blank”>
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/x86_64/debug/mc-debuginfo-4.6.0-14.10.x86_64.rpm

参考网址

来源: XF
名称: midnight-commander-format-string(16021)
链接:http://xforce.iss.net/xforce/xfdb/16021

来源: REDHAT
名称: RHSA-2004:172
链接:http://www.redhat.com/support/errata/RHSA-2004-172.html

来源: SUSE
名称: SuSE-SA:2004:012
链接:http://www.novell.com/linux/security/advisories/2004_12_mc.html

来源: DEBIAN
名称: DSA-497
链接:http://www.debian.org/security/2004/dsa-497

来源: GENTOO
名称: GLSA-200405-21
链接:http://security.gentoo.org/glsa/glsa-200405-21.xml

来源: MANDRAKE
名称: MDKSA-2004:039
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2004:039

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享