tcpdump BGP ‘bgp_update_print’函数 拒绝服务漏洞

漏洞信息详情

tcpdump BGP ‘bgp_update_print’函数 拒绝服务漏洞

漏洞简介

tcpdump 3.x中的bgp_update_print函数存在安全漏洞,由于没有正确处理decode_prefix4函数的-1返回值,远程攻击者可借助一个特制的BGP包来触发拒绝服务攻击(无限循环)。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

IBM AIX 5.3

IBM IY77141

http://www.ibm.com/support/

LBL libpcap 0.8.3

RedHat libpcap-0.8.3-6.FC2.3.legacy.i386.rpm

Fedora Core 2:

http://download.fedoralegacy.org/fedora/2/updates/i386/libpcap-0.8.3-6 .FC2.3.legacy.i386.rpm

IPCop IPCop 1.4.1

IPCop IPCop 1.4.6

http://ipcop.org/modules.php?op=modload&name=Downloads&file=index&req= viewdownload&cid=3&orderby=dateD

IPCop IPCop 1.4.8

http://sourceforge.net/project/showfiles.php?group_id=40604&package_id =35093&release_id=351848

IPCop IPCop 1.4.2

IPCop IPCop 1.4.6

http://ipcop.org/modules.php?op=modload&name=Downloads&file=index&req= viewdownload&cid=3&orderby=dateD

IPCop IPCop 1.4.8

http://sourceforge.net/project/showfiles.php?group_id=40604&package_id =35093&release_id=351848

IPCop IPCop 1.4.4

IPCop IPCop 1.4.6

http://ipcop.org/modules.php?op=modload&name=Downloads&file=index&req= viewdownload&cid=3&orderby=dateD

IPCop IPCop 1.4.8

http://sourceforge.net/project/showfiles.php?group_id=40604&package_id =35093&release_id=351848

IPCop IPCop 1.4.5

IPCop IPCop 1.4.6

http://ipcop.org/modules.php?op=modload&name=Downloads&file=index&req= viewdownload&cid=3&orderby=dateD

IPCop IPCop 1.4.8

http://sourceforge.net/project/showfiles.php?group_id=40604&package_id =35093&release_id=351848

IPCop IPCop 1.4.6

IPCop IPCop 1.4.8

http://sourceforge.net/project/showfiles.php?group_id=40604&package_id =35093&release_id=351848

MandrakeSoft Linux Mandrake 10.1

Mandriva tcpdump-3.8.3-2.2.101mdk.i586.rpm

Mandrakelinux 10.1:

http://www.mandriva.com/en/download

Mandriva tcpdump-3.8.3-2.2.101mdk.src.rpm

Mandrakelinux 10.1:

http://www.mandriva.com/en/download

MandrakeSoft Linux Mandrake 10.1 x86_64

Mandriva tcpdump-3.8.3-2.2.101mdk.src.rpm

Mandrakelinux 10.1/X86_64:

http://www.mandriva.com/en/download

Mandriva tcpdump-3.8.3-2.2.101mdk.x86_64.rpm

Mandrakelinux 10.1/X86_64:

http://www.mandriva.com/en/download

MandrakeSoft Linux Mandrake 10.2

Mandriva tcpdump-3.8.3-2.2.102mdk.i586.rpm

Mandrakelinux 10.2

http://www.mandriva.com/en/download

Mandriva tcpdump-3.8.3-2.2.102mdk.src.rpm

Mandrakelinux 10.2

http://www.mandriva.com/en/download

MandrakeSoft Linux Mandrake 10.2 x86_64

Mandriva tcpdump-3.8.3-2.2.102mdk.src.rpm

Mandrakelinux 10.2/X86_64:

http://www.mandriva.com/en/download

Mandriva tcpdump-3.8.3-2.2.102mdk.x86_64.rpm

Mandrakelinux 10.2/X86_64:

http://www.mandriva.com/en/download

LBL tcpdump 3.7.2

RedHat arpwatch-2.1a11-7.9.4.legacy.i386.rpm

Red Hat Linux 9:

http://download.fedoralegacy.org/redhat/9/updates/i386/arpwatch-2.1a11 -7.9.4.legacy.i386.rpm

RedHat arpwatch-2.1a11-8.fc1.3.legacy.i386.rpm

Fedora Core 1:

http://download.fedoralegacy.org/fedora/1/updates/i386/arpwatch-2.1a11 -8.fc1.3.legacy.i386.rpm

RedHat tcpdump-3.7.2-7.9.4.legacy.i386.rpm

Red Hat Linux 9:

http://download.fedoralegacy.org/redhat/9/updates/i386/tcpdump-3.7.2-7 .9.4.legacy.i386.rpm

RedHat tcpdump-3.7.2-8.fc1.3.legacy.i386.rpm

Fedora Core 1:

http://download.fedoralegacy.org/fedora/1/updates/i386/tcpdump-3.7.2-8 .fc1.3.legacy.i386.rpm

参考网址

来源: MISC

链接:https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=159208

来源: TRUSTIX

名称: 2005-0028

链接:http://www.trustix.org/errata/2005/0028/

来源: FEDORA

名称: FEDORA-2005-406

链接:http://www.redhat.com/archives/fedora-announce-list/2005-June/msg00007.html

来源: SECUNIA

名称: 15634

链接:http://secunia.com/advisories/15634/

来源: BID

名称: 13906

链接:http://www.securityfocus.com/bid/13906

来源: FEDORA

名称: FLSA:156139

链接:http://www.securityfocus.com/archive/1/archive/1/430292/100/0/threaded

来源: REDHAT

名称: RHSA-2005:505

链接:http://www.redhat.com/support/errata/RHSA-2005-505.html

来源: DEBIAN

名称: DSA-854

链接:http://www.debian.org/security/2005/dsa-854

来源: SECUNIA

名称: 17118

链接:http://secunia.com/advisories/17118

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享