漏洞信息详情
OpenSSL DER_CHOP不安全临时文件创建漏洞
- CNNVD编号:CNNVD-200502-020
- 危害等级: 低危
- CVE编号:
CVE-2004-0975
- 漏洞类型:
设计错误
- 发布时间:
2005-02-09
- 威胁类型:
本地
- 更新时间:
2005-10-20
- 厂 商:
mandrakesoft - 漏洞来源:
The individual or … -
漏洞简介
OpenSSL是一套开放源代码的SSL套件。
Trustix Secure Linux 1.5至2.1以及其他操作系统的openssl程序包中的der_chop脚本,可让本地用户通过象征性的链接攻击临时文件,从而覆盖这些文件。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
OpenSSL Project OpenSSL 0.9.6 c
-
Debian libssl-dev_0.9.6c-2.woody.7_arm.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
6c-2.woody.7_arm.deb
Debian libssl-dev_0.9.6c-2.woody.7_hppa.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
6c-2.woody.7_hppa.deb
Debian libssl-dev_0.9.6c-2.woody.7_i386.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
6c-2.woody.7_i386.deb
Debian libssl-dev_0.9.6c-2.woody.7_ia64.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
6c-2.woody.7_ia64.deb
Debian libssl-dev_0.9.6c-2.woody.7_m68k.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
6c-2.woody.7_m68k.deb
Debian libssl-dev_0.9.6c-2.woody.7_mips.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
6c-2.woody.7_mips.deb
Debian libssl-dev_0.9.6c-2.woody.7_mipsel.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
6c-2.woody.7_mipsel.deb
Debian libssl-dev_0.9.6c-2.woody.7_powerpc.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
6c-2.woody.7_powerpc.deb
Debian libssl-dev_0.9.6c-2.woody.7_s390.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
6c-2.woody.7_s390.deb
Debian libssl-dev_0.9.6c-2.woody.7_sparc.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
6c-2.woody.7_sparc.deb
Debian libssl0.9.6_0.9.6c-2.woody.7_alpha.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
.6c-2.woody.7_alpha.deb
Debian libssl0.9.6_0.9.6c-2.woody.7_arm.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
.6c-2.woody.7_arm.deb
Debian libssl0.9.6_0.9.6c-2.woody.7_hppa.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
.6c-2.woody.7_hppa.deb
Debian libssl0.9.6_0.9.6c-2.woody.7_i386.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
.6c-2.woody.7_i386.deb
Debian libssl0.9.6_0.9.6c-2.woody.7_ia64.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
.6c-2.woody.7_ia64.deb
Debian libssl0.9.6_0.9.6c-2.woody.7_m68k.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
.6c-2.woody.7_m68k.deb
Debian libssl0.9.6_0.9.6c-2.woody.7_mips.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
.6c-2.woody.7_mips.deb
Debian libssl0.9.6_0.9.6c-2.woody.7_mipsel.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
.6c-2.woody.7_mipsel.deb
Debian libssl0.9.6_0.9.6c-2.woody.7_powerpc.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
.6c-2.woody.7_powerpc.deb
Debian libssl0.9.6_0.9.6c-2.woody.7_s390.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
.6c-2.woody.7_s390.deb
Debian libssl0.9.6_0.9.6c-2.woody.7_sparc.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
.6c-2.woody.7_sparc.deb
Debian openssl_0.9.6c-2.woody.7_alpha.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c-
2.woody.7_alpha.deb
Debian openssl_0.9.6c-2.woody.7_arm.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c-
2.woody.7_arm.deb
Debian openssl_0.9.6c-2.woody.7_hppa.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c-
2.woody.7_hppa.deb
Debian openssl_0.9.6c-2.woody.7_i386.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c-
2.woody.7_i386.deb
Debian openssl_0.9.6c-2.woody.7_ia64.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c-
2.woody.7_ia64.deb
Debian openssl_0.9.6c-2.woody.7_m68k.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c-
2.woody.7_m68k.deb
Debian openssl_0.9.6c-2.woody.7_mips.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c-
2.woody.7_mips.deb
Debian openssl_0.9.6c-2.woody.7_mipsel.deb Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c-
2.woody.7_mipsel.deb
参考网址
来源: BID
名称: 11293
链接:http://www.securityfocus.com/bid/11293
来源: XF
名称: script-temporary-file-overwrite(17583)
链接:http://xforce.iss.net/xforce/xfdb/17583
来源: TRUSTIX
名称: 2004-0050
链接:http://www.trustix.org/errata/2004/0050
来源: GENTOO
名称: GLSA-200411-15
链接:http://www.gentoo.org/security/en/glsa/glsa-200411-15.xml
来源: DEBIAN
名称: DSA-603
链接:http://www.debian.org/security/2004/dsa-603
来源: SECUNIA
名称: 12973
链接:http://secunia.com/advisories/12973
来源: bugzilla.redhat.com
链接:http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136302
来源: REDHAT
名称: RHSA-2005:476
链接:http://www.redhat.com/support/errata/RHSA-2005-476.html
来源: US Government Resource: oval:org.mitre.oval:def:164
名称: oval:org.mitre.oval:def:164
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:164