漏洞信息详情
Info-ZIP 缓冲区溢出漏洞
- CNNVD编号:CNNVD-200503-034
- 危害等级: 超危
- CVE编号:
CVE-2004-1010
- 漏洞类型:
缓冲区溢出
- 发布时间:
2005-03-01
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
info-zip - 漏洞来源:
The individual res… -
漏洞简介
Info-Zip 2.3及可能的早期版本在使用递归文件夹压缩时存在缓冲区溢出,远程攻击者可以通过含有长文件名的ZIP文件执行任意代码。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Slackware Linux -current
Slackware infozip-5.52-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/a/in fozip-5.52-i486-1.tgz
Slackware Linux 10.0
Slackware infozip-5.52-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/ infozip-5.52-i486-1.tgz
Slackware Linux 10.1
Slackware infozip-5.52-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/ infozip-5.52-i486-1.tgz
Info-ZIP Zip 2.3
Debian zip_2.30-5woody2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_al pha.deb
Debian zip_2.30-5woody2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_ar m.deb
Debian zip_2.30-5woody2_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_hp pa.deb
Debian zip_2.30-5woody2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_i3 86.deb
Debian zip_2.30-5woody2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_ia 64.deb
Debian zip_2.30-5woody2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_m6 8k.deb
Debian zip_2.30-5woody2_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_mi ps.deb
Debian zip_2.30-5woody2_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_mi psel.deb
Debian zip_2.30-5woody2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_po werpc.deb
Debian zip_2.30-5woody2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_s3 90.deb
Debian zip_2.30-5woody2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/z/zip/zip_2.30-5woody2_sp arc.deb
Fedora zip-2.3-26.2.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora zip-2.3-26.2.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora zip-2.3-26.3.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
Fedora zip-2.3-26.3.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
Fedora zip-debuginfo-2.3-26.2.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora zip-debuginfo-2.3-26.2.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora zip-debuginfo-2.3-26.3.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
Fedora zip-debuginfo-2.3-26.3.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
Mandrake zip-2.3-11.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php
Mandrake zip-2.3-11.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php
Mandrake zip-2.3-11.1.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php
Mandrake zip-2.3-11.1.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php
Mandrake zip-2.3-11.1.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php
Mandrake zip-2.3-11.1.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php
Mandrake zip-2.3-9.1.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php
Mandrake zip-2.3-9.1.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php
RedHat zip-2.3-26.1.0.7.3.legacy.i386.rpm
参考网址
来源: BID
名称: 11603
链接:http://www.securityfocus.com/bid/11603
来源: FEDORA
名称: FLSA:2255
链接:https://bugzilla.fedora.us/show_bug.cgi?id=2255
来源: MISC
链接:http://www.hexview.com/docs/20041103-1.txt
来源: DEBIAN
名称: DSA-624
链接:http://www.debian.org/security/2005/dsa-624
来源: FULLDISC
名称: 20041103 [HV-MED] Zip/Linux long path buffer overflow
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028379.html
来源: XF
名称: infozip-compressed-folder-bo(17956)
链接:http://xforce.iss.net/xforce/xfdb/17956
来源: UBUNTU
名称: USN-18-1
链接:http://www.ubuntulinux.org/support/documentation/usn/usn-18-1
来源: TURBO
名称: TLSA-2005-18
链接:http://www.turbolinux.com/security/2005/TLSA-2005-18.txt
来源: REDHAT
名称: RHSA-2004:634
链接:http://www.redhat.com/support/errata/RHSA-2004-634.html
来源: MANDRAKE
名称: MDKSA-2004:141
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2004:141
来源: CIAC
名称: P-072
链接:http://www.ciac.org/ciac/bulletins/p-072.shtml
来源: GENTOO
名称: GLSA-200411-16
链接:http://security.gentoo.org/glsa/glsa-200411-16.xml
来源: BUGTRAQ
名称: 20041103 [HV-MED] Zip/Linux long path buffer overflow
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=109958840611053&w=2