漏洞信息详情
ARJ Software 目录遍历漏洞
- CNNVD编号:CNNVD-200503-030
- 危害等级: 中危
- CVE编号:
CVE-2004-1027
- 漏洞类型:
路径遍历
- 发布时间:
2005-03-01
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
gentoo - 漏洞来源:
Disclosure of this… -
漏洞简介
unarj中的-x(抽取)命令行选项中存在目录遍历漏洞,远程攻击者可以通过文件名含有..序列的arj归档文件覆盖任意文件。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
ARJ Software Inc. UNARJ 2.43
Debian unarj_2.43-3woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3woody1_alpha.deb
Debian unarj_2.43-3woody1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3woody1_arm.deb
Debian unarj_2.43-3woody1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3woody1_hppa.deb
Debian unarj_2.43-3woody1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3woody1_i386.deb
Debian unarj_2.43-3woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3woody1_ia64.deb
Debian unarj_2.43-3woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3woody1_m68k.deb
Debian unarj_2.43-3woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3woody1_powerpc.deb
Debian unarj_2.43-3woody1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3woody1_s390.deb
Debian unarj_2.43-3woody1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3woody1_sparc.deb
RedHat unarj-2.63a-4.0.7.3.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/7.3/updates/i386/unarj-2.63a-4.0.7.3.1.legacy.i386.rpm
ARJ Software Inc. UNARJ 2.63 a
Fedora unarj-2.63a-7.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora unarj-2.63a-7.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora unarj-debuginfo-2.63a-7.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora unarj-debuginfo-2.63a-7.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
RedHat unarj-2.63a-4.0.9.1.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/9/updates/i386/unarj-2.63a-4.0.9.1.legacy.i386.rpm
RedHat unarj-2.63a-4.1.1.legacy.i386.rpm
http://download.fedoralegacy.org/fedora/1/updates/i386/unarj-2.63a-4.1.1.legacy.i386.rpm
参考网址
来源: BID
名称: 11436
链接:http://www.securityfocus.com/bid/11436
来源: XF
名称: unarj-directory-traversal(17684)
链接:http://xforce.iss.net/xforce/xfdb/17684
来源: REDHAT
名称: RHSA-2005:007
链接:http://www.redhat.com/support/errata/RHSA-2005-007.html
来源: DEBIAN
名称: DSA-652
链接:http://www.debian.org/security/2005/dsa-652
来源: DEBIAN
名称: DSA-628
链接:http://www.debian.org/security/2005/dsa-628
来源: GENTOO
名称: GLSA-200411-29
链接:http://security.gentoo.org/glsa/glsa-200411-29.xml
来源: FEDORA
名称: FLSA:2272
链接:http://lwn.net/Articles/121827/
来源: FULLDISC
名称: 20041010 unarj dir-transversal bug (../../../..)
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/027348.html