漏洞信息详情
bsmtpd远程命令注入漏洞
- CNNVD编号:CNNVD-200502-097
- 危害等级: 高危
- CVE编号:
CVE-2005-0107
- 漏洞类型:
输入验证
- 发布时间:
2005-02-25
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
debian - 漏洞来源:
-
漏洞简介
BSMTP是一种用于UUCP环境下批量发送邮件的工具。
BSMTP在处理用户请求参数时存在输入验证漏洞,远程攻击者可能利用此漏洞在服务器上执行任意命令。
BSMTP的bsmtpd没有正确过滤用户请求参数可能包含的带有Shell转义符的系统命令,攻击者可以通过在输入参数中插入恶意命令以bsmtpd的权限执行。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
bsmtpd bsmtpd 2.3
Debian bsmtpd_2.3pl8b-12woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_alpha.deb
Debian bsmtpd_2.3pl8b-12woody1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_arm.deb
Debian bsmtpd_2.3pl8b-12woody1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_hppa.deb
Debian bsmtpd_2.3pl8b-12woody1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_i386.deb
Debian bsmtpd_2.3pl8b-12woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_ia64.deb
Debian bsmtpd_2.3pl8b-12woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_m68k.deb
Debian bsmtpd_2.3pl8b-12woody1_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_mips.deb
Debian bsmtpd_2.3pl8b-12woody1_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_mipsel.deb
Debian bsmtpd_2.3pl8b-12woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_powerpc.deb
Debian bsmtpd_2.3pl8b-12woody1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_s390.deb
Debian bsmtpd_2.3pl8b-12woody1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_sparc.deb