bsmtpd远程命令注入漏洞

漏洞信息详情

bsmtpd远程命令注入漏洞

漏洞简介

BSMTP是一种用于UUCP环境下批量发送邮件的工具。

BSMTP在处理用户请求参数时存在输入验证漏洞,远程攻击者可能利用此漏洞在服务器上执行任意命令。

BSMTP的bsmtpd没有正确过滤用户请求参数可能包含的带有Shell转义符的系统命令,攻击者可以通过在输入参数中插入恶意命令以bsmtpd的权限执行。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

bsmtpd bsmtpd 2.3

Debian bsmtpd_2.3pl8b-12woody1_alpha.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_alpha.deb

Debian bsmtpd_2.3pl8b-12woody1_arm.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_arm.deb

Debian bsmtpd_2.3pl8b-12woody1_hppa.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_hppa.deb

Debian bsmtpd_2.3pl8b-12woody1_i386.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_i386.deb

Debian bsmtpd_2.3pl8b-12woody1_ia64.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_ia64.deb

Debian bsmtpd_2.3pl8b-12woody1_m68k.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_m68k.deb

Debian bsmtpd_2.3pl8b-12woody1_mips.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_mips.deb

Debian bsmtpd_2.3pl8b-12woody1_mipsel.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_mipsel.deb

Debian bsmtpd_2.3pl8b-12woody1_powerpc.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_powerpc.deb

Debian bsmtpd_2.3pl8b-12woody1_s390.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_s390.deb

Debian bsmtpd_2.3pl8b-12woody1_sparc.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-1 2woody1_sparc.deb

参考网址

来源: DEBIAN

名称: DSA-690

链接:http://www.debian.org/security/2005/dsa-690

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享