OpenSSL DER_CHOP不安全临时文件创建漏洞

漏洞信息详情

OpenSSL DER_CHOP不安全临时文件创建漏洞

漏洞简介

OpenSSL是一套开放源代码的SSL套件。
Trustix Secure Linux 1.5至2.1以及其他操作系统的openssl程序包中的der_chop脚本,可让本地用户通过象征性的链接攻击临时文件,从而覆盖这些文件。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
OpenSSL Project OpenSSL 0.9.6 c

    Debian libssl-dev_0.9.6c-2.woody.7_arm.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
    6c-2.woody.7_arm.deb
    Debian libssl-dev_0.9.6c-2.woody.7_hppa.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
    6c-2.woody.7_hppa.deb
    Debian libssl-dev_0.9.6c-2.woody.7_i386.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
    6c-2.woody.7_i386.deb
    Debian libssl-dev_0.9.6c-2.woody.7_ia64.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
    6c-2.woody.7_ia64.deb
    Debian libssl-dev_0.9.6c-2.woody.7_m68k.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
    6c-2.woody.7_m68k.deb
    Debian libssl-dev_0.9.6c-2.woody.7_mips.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
    6c-2.woody.7_mips.deb
    Debian libssl-dev_0.9.6c-2.woody.7_mipsel.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
    6c-2.woody.7_mipsel.deb
    Debian libssl-dev_0.9.6c-2.woody.7_powerpc.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
    6c-2.woody.7_powerpc.deb
    Debian libssl-dev_0.9.6c-2.woody.7_s390.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
    6c-2.woody.7_s390.deb
    Debian libssl-dev_0.9.6c-2.woody.7_sparc.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.
    6c-2.woody.7_sparc.deb
    Debian libssl0.9.6_0.9.6c-2.woody.7_alpha.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
    .6c-2.woody.7_alpha.deb
    Debian libssl0.9.6_0.9.6c-2.woody.7_arm.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
    .6c-2.woody.7_arm.deb
    Debian libssl0.9.6_0.9.6c-2.woody.7_hppa.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
    .6c-2.woody.7_hppa.deb
    Debian libssl0.9.6_0.9.6c-2.woody.7_i386.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
    .6c-2.woody.7_i386.deb
    Debian libssl0.9.6_0.9.6c-2.woody.7_ia64.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
    .6c-2.woody.7_ia64.deb
    Debian libssl0.9.6_0.9.6c-2.woody.7_m68k.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
    .6c-2.woody.7_m68k.deb
    Debian libssl0.9.6_0.9.6c-2.woody.7_mips.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
    .6c-2.woody.7_mips.deb
    Debian libssl0.9.6_0.9.6c-2.woody.7_mipsel.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
    .6c-2.woody.7_mipsel.deb
    Debian libssl0.9.6_0.9.6c-2.woody.7_powerpc.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
    .6c-2.woody.7_powerpc.deb
    Debian libssl0.9.6_0.9.6c-2.woody.7_s390.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
    .6c-2.woody.7_s390.deb
    Debian libssl0.9.6_0.9.6c-2.woody.7_sparc.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.6_0.9
    .6c-2.woody.7_sparc.deb
    Debian openssl_0.9.6c-2.woody.7_alpha.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c-
    2.woody.7_alpha.deb
    Debian openssl_0.9.6c-2.woody.7_arm.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c-
    2.woody.7_arm.deb
    Debian openssl_0.9.6c-2.woody.7_hppa.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c-
    2.woody.7_hppa.deb
    Debian openssl_0.9.6c-2.woody.7_i386.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c-
    2.woody.7_i386.deb
    Debian openssl_0.9.6c-2.woody.7_ia64.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c-
    2.woody.7_ia64.deb
    Debian openssl_0.9.6c-2.woody.7_m68k.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c-
    2.woody.7_m68k.deb
    Debian openssl_0.9.6c-2.woody.7_mips.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c-
    2.woody.7_mips.deb
    Debian openssl_0.9.6c-2.woody.7_mipsel.deb Debian GNU/Linux 3.0 alias woody
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.6c-
    2.woody.7_mipsel.deb

参考网址

来源: BID
名称: 11293
链接:http://www.securityfocus.com/bid/11293

来源: XF
名称: script-temporary-file-overwrite(17583)
链接:http://xforce.iss.net/xforce/xfdb/17583

来源: TRUSTIX
名称: 2004-0050
链接:http://www.trustix.org/errata/2004/0050

来源: GENTOO
名称: GLSA-200411-15
链接:http://www.gentoo.org/security/en/glsa/glsa-200411-15.xml

来源: DEBIAN
名称: DSA-603
链接:http://www.debian.org/security/2004/dsa-603

来源: SECUNIA
名称: 12973
链接:http://secunia.com/advisories/12973

来源: bugzilla.redhat.com
链接:http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136302

来源: REDHAT
名称: RHSA-2005:476
链接:http://www.redhat.com/support/errata/RHSA-2005-476.html

来源: US Government Resource: oval:org.mitre.oval:def:164
名称: oval:org.mitre.oval:def:164
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:164

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享