漏洞信息详情
Red Hat redhat-config-nfs Exported共享配置漏洞
- CNNVD编号:CNNVD-200410-053
- 危害等级: 高危
- CVE编号:
CVE-2004-0750
- 漏洞类型:
配置错误
- 发布时间:
2004-09-23
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
redhat - 漏洞来源:
John Buswell -
漏洞简介
Red Hat是一款开放源代码Linux操作系统,redhat-config-nfs用于对NFS共享进行建立,修改,删除操作。
Red Hat redhat-config-nfs配置存在问题,可导致部分选项失效,管理员忽视部分安全威胁。
redhat-config-nfs的一个漏洞当导出(export)多个主机时可使部分导出共享权限不正确。这是由于\”all_squash\”选项没有正确实施在所有列表主机上造成的。这个漏洞可导致管理员忽视部分安全威胁。
漏洞公告
厂商补丁:
RedHat
——
RedHat已经为此发布了一个安全公告(RHSA-2004:434-01)以及相应补丁:
RHSA-2004:434-01:Updated redhat-config-nfs package resolves several security issues
链接:http://www.auscert.org.au/render.html?it=4411” target=”_blank”>
http://www.auscert.org.au/render.html?it=4411
补丁下载:
Red Hat Enterprise Linux AS version 3:
SRPMS:
ftp://updates.redhat.com/enterprise/3AS/en/os/SRPMS/redhat-config-nfs-1.0.13-6.src.rpm
8ad0200a16439ba6341703e277b6edc0 redhat-config-nfs-1.0.13-6.src.rpm
noarch:
ddea963341fba763c3bd428f16c8fede redhat-config-nfs-1.0.13-6.noarch.rpm
Red Hat Desktop version 3:
SRPMS:
ftp://updates.redhat.com/enterprise/3desktop/en/os/SRPMS/redhat-config-nfs-1.0.13-6.src.rpm
8ad0200a16439ba6341703e277b6edc0 redhat-config-nfs-1.0.13-6.src.rpm
noarch:
ddea963341fba763c3bd428f16c8fede redhat-config-nfs-1.0.13-6.noarch.rpm
Red Hat Enterprise Linux ES version 3:
SRPMS:
ftp://updates.redhat.com/enterprise/3ES/en/os/SRPMS/redhat-config-nfs-1.0.13-6.src.rpm
8ad0200a16439ba6341703e277b6edc0 redhat-config-nfs-1.0.13-6.src.rpm
noarch:
ddea963341fba763c3bd428f16c8fede redhat-config-nfs-1.0.13-6.noarch.rpm
Red Hat Enterprise Linux WS version 3:
SRPMS:
ftp://updates.redhat.com/enterprise/3WS/en/os/SRPMS/redhat-config-nfs-1.0.13-6.src.rpm
8ad0200a16439ba6341703e277b6edc0 redhat-config-nfs-1.0.13-6.src.rpm
noarch:
ddea963341fba763c3bd428f16c8fede redhat-config-nfs-1.0.13-6.noarch.rpm
可使用下列命令安装补丁:
rpm -Fvh [文件名]
参考网址
来源: REDHAT
名称: RHSA-2004:434
链接:http://www.redhat.com/support/errata/RHSA-2004-434.html
来源: XF
名称: red-hat-permission-gain-privileges(17478)
链接:http://xforce.iss.net/xforce/xfdb/17478
来源: OVAL
名称: oval:org.mitre.oval:def:10696
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10696
来源: BID
名称: 11240
链接:http://www.securityfocus.com/bid/11240
来源: FEDORA
名称: FLSA:152787
链接:http://www.securityfocus.com/archive/1/archive/1/419762/100/0/threaded