ARJ Software 目录遍历漏洞

漏洞信息详情

ARJ Software 目录遍历漏洞

漏洞简介

unarj中的-x(抽取)命令行选项中存在目录遍历漏洞,远程攻击者可以通过文件名含有..序列的arj归档文件覆盖任意文件。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

ARJ Software Inc. UNARJ 2.43

Debian unarj_2.43-3woody1_alpha.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3woody1_alpha.deb

Debian unarj_2.43-3woody1_arm.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3woody1_arm.deb

Debian unarj_2.43-3woody1_hppa.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3woody1_hppa.deb

Debian unarj_2.43-3woody1_i386.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3woody1_i386.deb

Debian unarj_2.43-3woody1_ia64.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3woody1_ia64.deb

Debian unarj_2.43-3woody1_m68k.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3woody1_m68k.deb

Debian unarj_2.43-3woody1_powerpc.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3woody1_powerpc.deb

Debian unarj_2.43-3woody1_s390.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3woody1_s390.deb

Debian unarj_2.43-3woody1_sparc.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/non-free/u/unarj/unarj_2.43-3woody1_sparc.deb

RedHat unarj-2.63a-4.0.7.3.1.legacy.i386.rpm

http://download.fedoralegacy.org/redhat/7.3/updates/i386/unarj-2.63a-4.0.7.3.1.legacy.i386.rpm

ARJ Software Inc. UNARJ 2.63 a

Fedora unarj-2.63a-7.i386.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora unarj-2.63a-7.x86_64.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora unarj-debuginfo-2.63a-7.i386.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora unarj-debuginfo-2.63a-7.x86_64.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

RedHat unarj-2.63a-4.0.9.1.legacy.i386.rpm

http://download.fedoralegacy.org/redhat/9/updates/i386/unarj-2.63a-4.0.9.1.legacy.i386.rpm

RedHat unarj-2.63a-4.1.1.legacy.i386.rpm

http://download.fedoralegacy.org/fedora/1/updates/i386/unarj-2.63a-4.1.1.legacy.i386.rpm

参考网址

来源: BID

名称: 11436

链接:http://www.securityfocus.com/bid/11436

来源: XF

名称: unarj-directory-traversal(17684)

链接:http://xforce.iss.net/xforce/xfdb/17684

来源: REDHAT

名称: RHSA-2005:007

链接:http://www.redhat.com/support/errata/RHSA-2005-007.html

来源: DEBIAN

名称: DSA-652

链接:http://www.debian.org/security/2005/dsa-652

来源: DEBIAN

名称: DSA-628

链接:http://www.debian.org/security/2005/dsa-628

来源: GENTOO

名称: GLSA-200411-29

链接:http://security.gentoo.org/glsa/glsa-200411-29.xml

来源: FEDORA

名称: FLSA:2272

链接:http://lwn.net/Articles/121827/

来源: FULLDISC

名称: 20041010 unarj dir-transversal bug (../../../..)

链接:http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/027348.html

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享