漏洞信息详情
Midnight Commander多个未明安全漏洞
- CNNVD编号:CNNVD-200408-187
- 危害等级: 超危
- CVE编号:
CVE-2004-0226
- 漏洞类型:
未知
- 发布时间:
2004-04-30
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
midnight_commander - 漏洞来源:
Jacub Jelinek -
漏洞简介
Midnight Commander是一款强大的GNU/LINUX系统的文件管理器。
Midnight Commander存在多个未明漏洞,远程攻击者可以利用这些漏洞进行缓冲区溢出,进行符号连接攻击及拒绝服务等攻击。
Midnight Commander存在缓冲区溢出,不安全建立文件和目录及格式串问题,目前没有详细漏洞细节提供。
漏洞公告
厂商补丁:
Debian
——
http://www.debian.org/security/2004/dsa-497
MandrakeSoft
————
MandrakeSoft已经为此发布了一个安全公告(MDKSA-2004:039)以及相应补丁:
MDKSA-2004:039:Updated mc packages fix vulnerabilities
链接:http://www.linux-mandrake.com/en/security/2004/2004-039.php” target=”_blank”>
http://www.linux-mandrake.com/en/security/2004/2004-039.php
补丁下载:
Updated Packages:
Mandrakelinux 10.0:
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/RPMS/mc-4.6.0-6.1.100mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/SRPMS/mc-4.6.0-6.1.100mdk.src.rpm
Corporate Server 2.1:
Corporate Server 2.1/x86_64:
Mandrakelinux 9.1:
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/RPMS/mc-4.6.0-4.2.91mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/SRPMS/mc-4.6.0-4.2.91mdk.src.rpm
Mandrakelinux 9.1/PPC:
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/RPMS/mc-4.6.0-4.2.91mdk.ppc.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/9.1/SRPMS/mc-4.6.0-4.2.91mdk.src.rpm
Mandrakelinux 9.2:
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.2/RPMS/mc-4.6.0-4.2.92mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.2/SRPMS/mc-4.6.0-4.2.92mdk.src.rpm
Mandrakelinux 9.2/AMD64:
上述升级软件还可以在下列地址中的任意一个镜像ftp服务器上下载:
http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php
RedHat
——
RedHat已经为此发布了一个安全公告(RHSA-2004:173-00)以及相应补丁:
RHSA-2004:173-00:Updated mc packages resolve several vulnerabilities
链接:https://www.redhat.com/support/errata/RHSA-2004-173.html” target=”_blank”>https://www.redhat.com/support/errata/RHSA-2004-173.html
补丁下载:
Fedora Upgrade mc-4.6.0-14.10.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386/mc-4.6.0-14.10.i386.rpm” target=”_blank”>
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386/mc-4.6.0-14.10.i386.rpm
Fedora Upgrade mc-debuginfo-4.6.0-14.10.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386/debug/mc-debuginfo-4.6.0-14.10.i386.rpm” target=”_blank”>
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386/debug/mc-debuginfo-4.6.0-14.10.i386.rpm
Fedora Upgrade mc-4.6.0-14.10.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/x86_64/mc-4.6.0-14.10.x86_64.rpm” target=”_blank”>
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/x86_64/mc-4.6.0-14.10.x86_64.rpm
Fedora Upgrade mc-debuginfo-4.6.0-14.10.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/x86_64/debug/mc-debuginfo-4.6.0-14.10.x86_64.rpm” target=”_blank”>
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/x86_64/debug/mc-debuginfo-4.6.0-14.10.x86_64.rpm
参考网址
来源: REDHAT
名称: RHSA-2004:172
链接:http://www.redhat.com/support/errata/RHSA-2004-172.html
来源: XF
名称: midnight-commander-local-privileges(16016)
链接:http://xforce.iss.net/xforce/xfdb/16016
来源: SUSE
名称: SuSE-SA:2004:012
链接:http://www.novell.com/linux/security/advisories/2004_12_mc.html
来源: DEBIAN
名称: DSA-497
链接:http://www.debian.org/security/2004/dsa-497
来源: GENTOO
名称: GLSA-200405-21
链接:http://security.gentoo.org/glsa/glsa-200405-21.xml
来源: MANDRAKE
名称: MDKSA-2004:039
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2004:039