Speedtouch USB驱动程序本地格式串漏洞

漏洞信息详情

Speedtouch USB驱动程序本地格式串漏洞

漏洞简介

Speedtouch USB驱动程序1.3.1以前的版本存在格式串漏洞。本地用户借助(1)modem_run, (2)pppoa2,或者(3)pppoa3执行任意代码。

漏洞公告

Gentoo Linux has released advisory GLSA 200411-04 along with fixes dealing with this issue. Gentoo has advised that all Speedtouch USB driver users should upgrade to the latest version:
# emerge –sync
# emerge –ask –oneshot –verbose “>=net-dialup/speedtouch-1.3.1”
For more information please see the referenced advisory.
MandrakeSoft has issued fixes for Mandrake Linux. See advisory MDKSA-2004:130 in the reference section.
Speedtouch USB Driver 1.3.1 is available to address this issue:
Speedtouch USB Driver Speedtouch USB Driver 1.0

Speedtouch USB Driver Speedtouch USB Driver 1.1

Speedtouch USB Driver Speedtouch USB Driver 1.2

Speedtouch USB Driver Speedtouch USB Driver 1.2 beta2

Speedtouch USB Driver Speedtouch USB Driver 1.2 beta1

Speedtouch USB Driver Speedtouch USB Driver 1.2 beta3

Speedtouch USB Driver Speedtouch USB Driver 1.3

参考网址

来源: XF
名称: speedtouch-format-string(17792)
链接:http://xforce.iss.net/xforce/xfdb/17792

来源: www.mail-archive.com
链接:http://www.mail-archive.com/speedtouch@ml.free.fr/msg06688.html

来源: speedtouch.sourceforge.net
链接:http://speedtouch.sourceforge.net/index.php?/news.en.html

来源: sourceforge.net
链接:http://sourceforge.net/project/showfiles.php?group_id=32758&package_id=28264&release_id=271734

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享