漏洞信息详情
Midnight Commander fish.c执行程序漏洞
- CNNVD编号:CNNVD-200504-064
- 危害等级: 高危
- CVE编号:
CVE-2004-1175
- 漏洞类型:
资料不足
- 发布时间:
2005-04-14
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
turbolinux - 漏洞来源:
Discovery is credi… -
漏洞简介
Midnight Commander 是 Unix系统上流行的文件管理工具,类似MS-DOS里的PcTools。
Midnight commander中的fish.c使得远程攻击者可以通过\”不安全的文件名引用\”,可能使用外壳元字符,来执行任意程序。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Debian Linux 3.0 s/390
Debian gmc_4.5.55-1.2woody5_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/gmc_4.5.55-1.2woody5 _s390.deb
Debian mc-common_4.5.55-1.2woody5_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/mc-common_4.5.55-1.2 woody5_s390.deb
Debian mc_4.5.55-1.2woody5_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/mc_4.5.55-1.2woody5_ s390.deb
Debian Linux 3.0 alpha
Debian gmc_4.5.55-1.2woody5_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/gmc_4.5.55-1.2woody5 _alpha.deb
Debian mc-common_4.5.55-1.2woody5_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/mc-common_4.5.55-1.2 woody5_alpha.deb
Debian mc_4.5.55-1.2woody5_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/mc_4.5.55-1.2woody5_ alpha.deb
Debian Linux 3.0 mips
Debian gmc_4.5.55-1.2woody5_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/gmc_4.5.55-1.2woody5 _mips.deb
Debian mc-common_4.5.55-1.2woody5_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/mc-common_4.5.55-1.2 woody5_mips.deb
Debian mc_4.5.55-1.2woody5_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/mc_4.5.55-1.2woody5_ mips.deb
Debian Linux 3.0 mipsel
Debian gmc_4.5.55-1.2woody5_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/gmc_4.5.55-1.2woody5 _mipsel.deb
Debian mc-common_4.5.55-1.2woody5_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/mc-common_4.5.55-1.2 woody5_mipsel.deb
Debian mc_4.5.55-1.2woody5_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/mc_4.5.55-1.2woody5_ mipsel.deb
Debian Linux 3.0 m68k
Debian gmc_4.5.55-1.2woody5_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/gmc_4.5.55-1.2woody5 _m68k.deb
Debian mc-common_4.5.55-1.2woody5_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/mc-common_4.5.55-1.2 woody5_m68k.deb
Debian mc_4.5.55-1.2woody5_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/mc_4.5.55-1.2woody5_ m68k.deb
Debian Linux 3.0 hppa
Debian gmc_4.5.55-1.2woody5_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/gmc_4.5.55-1.2woody5 _hppa.deb
Debian mc-common_4.5.55-1.2woody5_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/mc-common_4.5.55-1.2 woody5_hppa.deb
Debian mc_4.5.55-1.2woody5_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/mc_4.5.55-1.2woody5_ hppa.deb
Debian Linux 3.0 arm
Debian gmc_4.5.55-1.2woody5_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/gmc_4.5.55-1.2woody5 _arm.deb
Debian mc-common_4.5.55-1.2woody5_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/mc-common_4.5.55-1.2 woody5_arm.deb
Debian mc_4.5.55-1.2woody5_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/mc_4.5.55-1.2woody5_ arm.deb
Debian Linux 3.0 sparc
Debian gmc_4.5.55-1.2woody5_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/gmc_4.5.55-1.2woody5 _sparc.deb
Debian mc-common_4.5.55-1.2woody5_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/mc-common_4.5.55-1.2 woody5_sparc.deb
Debian mc_4.5.55-1.2woody5_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/m/mc/mc_4.5.55-1.2woody5_ sparc.deb
Debian Linux 3.0 ia-64
Debian gmc_4.5.55-1.2woody5_ia64.deb
Debi
参考网址
来源: DEBIAN
名称: DSA-639
链接:http://www.debian.org/security/2005/dsa-639
来源: SECUNIA
名称: 13863
链接:http://secunia.com/advisories/13863/
来源: XF
名称: midnight-commander-command-execution(18906)
链接:http://xforce.iss.net/xforce/xfdb/18906
来源: SECTRACK
名称: 1012903
链接:http://securitytracker.com/id?1012903
来源: REDHAT
名称: RHSA-2005:512