漏洞信息详情
Linux内核 整数溢出漏洞
- CNNVD编号:CNNVD-200503-070
- 危害等级: 低危
- CVE编号:
CVE-2005-0180
- 漏洞类型:
边界条件错误
- 发布时间:
2005-03-07
- 威胁类型:
本地
- 更新时间:
2005-10-20
- 厂 商:
linux - 漏洞来源:
Discovery of this … -
漏洞简介
Linux 2.6.x scsi_ioctl.c的sg_scsi_ioctl函数存在多个整数符号错误,本地用户可以通过scsi ioctl参数中的负整数读取或修改内核内存,这些负整数在调用copy_from_user和copy_to_user函数之前可绕过最大长度检查。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Linux kernel 2.6.3
Mandriva kernel-2.6.3.29mdk-1-1mdk.i586.rpm
Corporate 3.0:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-2.6.3.29mdk-1-1mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-enterprise-2.6.3.29mdk-1-1mdk.i586.rpm
Corporate 3.0:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-i686-up-4GB-2.6.3.29mdk-1-1mdk.i586.rpm
Corporate 3.0:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-p3-smp-64GB-2.6.3.29mdk-1-1mdk.i586.rpm
Corporate 3.0:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-secure-2.6.3.29mdk-1-1mdk.i586.rpm
Corporate 3.0:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-secure-2.6.3.29mdk-1-1mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-smp-2.6.3.29mdk-1-1mdk.i586.rpm
Corporate 3.0:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-smp-2.6.3.29mdk-1-1mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-source-2.6.3-29mdk.i586.rpm
Corporate 3.0:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-source-2.6.3-29mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-source-stripped-2.6.3-29mdk.i586.rpm
Corporate 3.0:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-source-stripped-2.6.3-29mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3
Linux kernel 2.6.4
SuSE kernel-bigsmp-2.6.5-7.147.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-bigsmp-2.6 .5-7.147.i586.rpm
SuSE kernel-default-2.6.5-7.147.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-default-2. 6.5-7.147.i586.rpm
SuSE kernel-default-2.6.5-7.147.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kernel-defaul t-2.6.5-7.147.x86_64.rpm
SuSE kernel-docs-2.6.5-7.147.noarch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/noarch/kernel-docs-2.6 .5-7.147.noarch.rpm
SuSE kernel-smp-2.6.5-7.147.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-smp-2.6.5- 7.147.i586.rpm
SuSE kernel-smp-2.6.5-7.147.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kernel-smp-2. 6.5-7.147.x86_64.rpm
SuSE kernel-source-2.6.5-7.147.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-source-2.6 .5-7.147.i586.rpm
SuSE kernel-source-2.6.5-7.147.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kernel-source -2.6.5-7.147.x86_64.rpm
SuSE kernel-syms-2.6.5-7.147.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-syms-2.6.5 -7.147.i586.rpm
SuSE kernel-syms-2.6.5-7.147.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kernel-syms-2 .6.5-7.147.x86_64.rpm
SuSE ltmodem-2.6.2-38.13.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/ltmodem-2.6.2-38. 13.i586.rpm
Linux kernel 2.6.5
Fedora kernel-2.6.10-1.8_FC2.i586.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora kernel-2.6.10-1.8_FC2.i686.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora kernel-2.6.10-1.8_FC2.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora kernel-debuginfo-2.6.10-1.8_FC2.i586.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora kernel-debuginfo-2.6.10-1.8_FC2.i686.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora kernel-debuginfo-2.6.10-1.8_FC2.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora kernel-doc-2.6.10-1.8_FC2.noarch.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora kernel-smp-2.6.10-1.8_FC2.i586.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora kernel-smp-2.6.10-1.8_FC2.i686.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora kernel-smp-2.6.10-1.8_FC2.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora kernel-sourcecode-2.6.10-1.8_FC2.noarch.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
SuSE kernel-bigsmp-2.6.5-7.111.30.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-bigsmp-2.6 .5-7.111.30.i586.rpm
SuSE kernel-default-2.6.5-7.111.30.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-default-2. 6.5-7.111.30.i586.rpm
SuSE kernel-default-2.6.5-7.111.30.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kernel-defaul t-2.6.5-7.111.30.x86_64.rpm
SuSE kernel-smp-2.6.5-7.111.30.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-smp-2.6.5- 7.111.30.i586.rpm
SuSE kernel-smp-2.6.5-7.111.30.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kernel-smp-2. 6.5-7.111.30.x86_64.rpm
SuSE kernel-source-2.6.5-7.111.30.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-source-2.6 .5-7.111.30.i586.rpm
SuSE kernel-source-2.6.5-7.111.30.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kernel-source -2.6.5-7.111.30.x86_64.rpm
Linux kernel 2.6.8 rc1
Mandriva kernel-2.6.8.1.26mdk-1-1mdk.i586.rpm
Mandriva Linux 10.1:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-2.6.8.1.26mdk-1-1mdk.x86_64.rpm
Mandriva Linux 10.1/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-enterprise-2.6.8.1.26mdk-1-1mdk.i586.rpm
Mandriva Linux 10.1:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-i586-up-1GB-2.6.8.1.26mdk-1-1mdk.i586.rpm
Mandriva Linux 10.1:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-i686-up-64GB-2.6.8.1.26mdk-1-1mdk.i586.rpm
Mandriva Linux 10.1:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-secure-2.6.8.1.26mdk-1-1mdk.i586.rpm
Mandriva Linux 10.1:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-secure-2.6.8.1.26mdk-1-1mdk.x86_64.rpm
Mandriva Linux 10.1/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-smp-2.6.8.1.26mdk-1-1mdk.i586.rpm
Mandriva Linux 10.1:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-smp-2.6.8.1.26mdk-1-1mdk.x86_64.rpm
Mandriva Linux 10.1/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-source-2.6-2.6.8.1-26mdk.i586.rpm
Mandriva Linux 10.1:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-source-2.6-2.6.8.1-26mdk.x86_64.rpm
Mandriva Linux 10.1/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-source-stripped-2.6-2.6.8.1-26mdk.i586.rpm
Mandriva Linux 10.1:
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva kernel-source-stripped-2.6-2.6.8.1-26mdk.x86_64.rpm
Mandriva Linux 10.1/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3
Linux kernel 2.6.8
SuSE kernel-bigsmp-2.6.8-24.11.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/kernel-bigsmp-2.6 .8-24.11.i586.rpm
SuSE kernel-default-2.6.8-24.11.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/kernel-default-2. 6.8-24.11.i586.rpm
SuSE kernel-default-2.6.8-24.11.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/x86_64/kernel-defaul t-2.6.8-24.11.x86_64.rpm
SuSE kernel-smp-2.6.8-24.11.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/kernel-smp-2.6.8- 24.11.i586.rpm
SuSE kernel-smp-2.6.8-24.11.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/x86_64/kernel-smp-2. 6.8-24.11.x86_64.rpm
SuSE kernel-source-2.6.8-24.11.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/kernel-source-2.6 .8-24.11.i586.rpm
SuSE kernel-source-2.6.8-24.11.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/x86_64/kernel-source -2.6.8-24.11.x86_64.rpm
Linux kernel 2.6.9
Fedora kernel-2.6.10-1.737_FC3.i586.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
Fedora kernel-2.6.10-1.737_FC3.i686.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
Fedora kernel-2.6.10-1.737_FC3.x
参考网址
来源: REDHAT
名称: RHSA-2005:092
链接:http://www.redhat.com/support/errata/RHSA-2005-092.html
来源: FULLDISC
名称: 20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030660.html
来源: CONECTIVA
名称: CLA-2005:930
链接:http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=000930
来源: BID
名称: 12198
链接:http://www.securityfocus.com/bid/12198
来源: BUGTRAQ
名称: 20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories
链接:http://www.securityfocus.com/archive/1/386374
来源: MANDRIVA
名称: MDKSA-2005:219
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2005:219
来源: MANDRAKE
名称: MDKSA-2005:218
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2005:218
来源: SECUNIA
名称: 17826
链接:http://secunia.com/advisories/17826
来源: MANDRIVA
名称: MDKSA-2005:219
链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219
来源: MANDRAKE
名称: MDKSA-2005:218
链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:218