TNFTPD多个信号处理器远程超级用户妥协漏洞

漏洞信息详情

TNFTPD多个信号处理器远程超级用户妥协漏洞

漏洞简介

lukemftpd(也称为20040810之前的tnftpd)中的许多信号处理器竞争条件存在漏洞。远程已认证的攻击者可以导致服务拒绝或者执行任意代码。

漏洞公告

The vendor has released patches resolving these issues.
NetBSD has released advisory 2004-009 addressing this issue. Please see the referenced advisory for further information. Fixes are available from CVS for the NetBSD-current and NetBSD-2.0 branches.
Apple has released an advisory (APPLE-SA-0024-09-07) along with fixes to address this, and many other issues. Please see the referenced advisory for further information.
Heimdal has released an advisory (2004-09-13) along with version 0.6.3 to address this issue. Please see the referenced advisory for further information.
Gentoo Linux has released an advisory (GLSA 200409-19) to address this issue. Please see the referenced advisory for further information. Users of affected packages are urged to execute the following with superuser privileges:
emerge sync
emerge -pv “>=app-crypt/heimdal-0.6.3”
emerge “>=app-crypt/heimdal-0.6.3”
Debian Linux has released an advisory (DSA 551-1) along with fixes dealing with this issue. Please the referenced advisory for more information.
Sun has released an advisory (Sun Alert ID: 57655) with fixes to address these issues in Sun Java Desktop System (JDS) 2003 and Release 2 for the Linux platform. Please see the advisory in Web references for more information. Users may carry out the following actions from the launch bar to download the patch:
Launch >> Applications >> System Tools >> Online Update
Luke Mewburn TNFTPD 20031217

Sun Java Desktop System (JDS) 2003

  • Sun patch-9369

Heimdal Heimdal 0.3 f

Heimdal Heimdal 0.4 b

Heimdal Heimdal 0.4 d

Heimdal Heimdal 0.4 c

Heimdal Heimdal 0.4 a

Heimdal Heimdal 0.4 e

Heimdal Heimdal 0.5 .0

Heimdal Heimdal 0.5.1

Heimdal Heimdal 0.5.2

Heimdal Heimdal 0.5.3

Heimdal Heimdal 0.6

Heimdal Heimdal 0.6.1

Heimdal Heimdal 0.6.2

Luke Mewburn lukemftp 1.1

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享