Info-ZIP 缓冲区溢出漏洞

漏洞信息详情

Info-ZIP 缓冲区溢出漏洞

漏洞简介

Info-Zip 2.3及可能的早期版本在使用递归文件夹压缩时存在缓冲区溢出,远程攻击者可以通过含有长文件名的ZIP文件执行任意代码。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Slackware Linux -current

Slackware infozip-5.52-i486-1.tgz

ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/a/in fozip-5.52-i486-1.tgz

Slackware Linux 10.0

Slackware infozip-5.52-i486-1.tgz

ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/ infozip-5.52-i486-1.tgz

Slackware Linux 10.1

Slackware infozip-5.52-i486-1.tgz

ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/ infozip-5.52-i486-1.tgz

Info-ZIP Zip 2.3

Debian zip_2.30-5woody2_alpha.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_al pha.deb

Debian zip_2.30-5woody2_arm.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_ar m.deb

Debian zip_2.30-5woody2_hppa.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_hp pa.deb

Debian zip_2.30-5woody2_i386.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_i3 86.deb

Debian zip_2.30-5woody2_ia64.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_ia 64.deb

Debian zip_2.30-5woody2_m68k.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_m6 8k.deb

Debian zip_2.30-5woody2_mips.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_mi ps.deb

Debian zip_2.30-5woody2_mipsel.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_mi psel.deb

Debian zip_2.30-5woody2_powerpc.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_po werpc.deb

Debian zip_2.30-5woody2_s390.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_s3 90.deb

Debian zip_2.30-5woody2_sparc.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_sp arc.deb

Fedora zip-2.3-26.2.i386.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora zip-2.3-26.2.x86_64.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora zip-2.3-26.3.i386.rpm

RedHat Fedora Core 3

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

Fedora zip-2.3-26.3.x86_64.rpm

RedHat Fedora Core 3

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

Fedora zip-debuginfo-2.3-26.2.i386.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora zip-debuginfo-2.3-26.2.x86_64.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora zip-debuginfo-2.3-26.3.i386.rpm

RedHat Fedora Core 3

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

Fedora zip-debuginfo-2.3-26.3.x86_64.rpm

RedHat Fedora Core 3

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

Mandrake zip-2.3-11.1.100mdk.amd64.rpm

Mandrake Linux 10.0/AMD64

http://www.mandrakesecure.net/en/ftp.php

Mandrake zip-2.3-11.1.100mdk.i586.rpm

Mandrake Linux 10.0

http://www.mandrakesecure.net/en/ftp.php

Mandrake zip-2.3-11.1.101mdk.i586.rpm

Mandrake Linux 10.1

http://www.mandrakesecure.net/en/ftp.php

Mandrake zip-2.3-11.1.101mdk.x86_64.rpm

Mandrake Linux 10.1/x86_64

http://www.mandrakesecure.net/en/ftp.php

Mandrake zip-2.3-11.1.92mdk.amd64.rpm

Mandrake Linux 9.2/AMD64

http://www.mandrakesecure.net/en/ftp.php

Mandrake zip-2.3-11.1.92mdk.i586.rpm

Mandrake Linux 9.2

http://www.mandrakesecure.net/en/ftp.php

Mandrake zip-2.3-9.1.C21mdk.i586.rpm

Mandrake Corporate Server 2.1

http://www.mandrakesecure.net/en/ftp.php

Mandrake zip-2.3-9.1.C21mdk.x86_64.rpm

Mandrake Corporate Server 2.1/x86_64

http://www.mandrakesecure.net/en/ftp.php

RedHat zip-2.3-26.1.0.7.3.legacy.i386.rpm

http://download.fedoralegacy.org/r

参考网址

来源: BID

名称: 11603

链接:http://www.securityfocus.com/bid/11603

来源: FEDORA

名称: FLSA:2255

链接:https://bugzilla.fedora.us/show_bug.cgi?id=2255

来源: MISC

链接:http://www.hexview.com/docs/20041103-1.txt

来源: DEBIAN

名称: DSA-624

链接:http://www.debian.org/security/2005/dsa-624

来源: FULLDISC

名称: 20041103 [HV-MED] Zip/Linux long path buffer overflow

链接:http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028379.html

来源: XF

名称: infozip-compressed-folder-bo(17956)

链接:http://xforce.iss.net/xforce/xfdb/17956

来源: UBUNTU

名称: USN-18-1

链接:http://www.ubuntulinux.org/support/documentation/usn/usn-18-1

来源: TURBO

名称: TLSA-2005-18

链接:http://www.turbolinux.com/security/2005/TLSA-2005-18.txt

来源: REDHAT

名称: RHSA-2004:634

链接:http://www.redhat.com/support/errata/RHSA-2004-634.html

来源: MANDRAKE

名称: MDKSA-2004:141

链接:http://www.mandriva.com/security/advisories?name=MDKSA-2004:141

来源: CIAC

名称: P-072

链接:http://www.ciac.org/ciac/bulletins/p-072.shtml

来源: GENTOO

名称: GLSA-200411-16

链接:http://security.gentoo.org/glsa/glsa-200411-16.xml

来源: BUGTRAQ

名称: 20041103 [HV-MED] Zip/Linux long path buffer overflow

链接:http://marc.theaimsgroup.com/?l=bugtraq&m=109958840611053&w=2

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享