CVS Cvsbug.In Script 不安全临时文件创建漏洞

漏洞信息详情

CVS Cvsbug.In Script 不安全临时文件创建漏洞

漏洞简介

CVS 1.12.12及其早前版本中的cvsbug以不安全的方式创建临时文件。这使得本地用户可以借助于符号链接攻击重写任意文件并可执行任意代码。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

RedHat Fedora cvs-1.11.17-7.FC3.i386.rpm

Fedora Core 3

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

RedHat Fedora cvs-1.11.17-7.FC3.x86_64.rpm

Fedora Core 3

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

RedHat Fedora cvs-debuginfo-1.11.17-7.FC3.i386.rpm

Fedora Core 3

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

RedHat Fedora cvs-debuginfo-1.11.17-7.FC3.x86_64.rpm

Fedora Core 3

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

CVS CVS 1.11.19

RedHat Fedora cvs-1.11.19-9.i386.rpm

Fedora Core 4

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/

RedHat Fedora cvs-1.11.19-9.ppc.rpm

Fedora Core 4

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/

RedHat Fedora cvs-1.11.19-9.x86_64.rpm

Fedora Core 4

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/

RedHat Fedora cvs-debuginfo-1.11.19-9.i386.rpm

Fedora Core 4

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/

RedHat Fedora cvs-debuginfo-1.11.19-9.ppc.rpm

Fedora Core 4

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/

RedHat Fedora cvs-debuginfo-1.11.19-9.x86_64.rpm

Fedora Core 4

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/

SGI ProPack 3.0 SP6

SGI Patch 10212

http://support.sgi.com/

FreeBSD FreeBSD 4.11 -RELEASE-p3

FreeBSD cvsbug.patch

ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-05:20/cvsbug.patch

FreeBSD cvsbug.patch.asc

ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-05:20/cvsbug.patch.asc

FreeBSD FreeBSD 5.3

FreeBSD cvsbug.patch

ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-05:20/cvsbug.patch

FreeBSD cvsbug.patch.asc

ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-05:20/cvsbug.patch.asc

FreeBSD cvsbug53.patch

ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-05:20/cvsbug53.patch

FreeBSD cvsbug53.patch.asc

ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-05:20/cvsbug53.patch.asc

FreeBSD FreeBSD 5.4 -RELENG

FreeBSD cvsbug.patch

ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-05:20/cvsbug.patch

FreeBSD cvsbug.patch.asc

ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/patches/SA-05:20/cvsbug.patch.asc

参考网址

来源: bugzilla.redhat.com

链接:https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=166366

来源: REDHAT

名称: RHSA-2005:756

链接:http://www.redhat.com/support/errata/RHSA-2005-756.html

来源: VUPEN

名称: ADV-2005-1667

链接:http://www.frsirt.com/english/advisories/2005/1667

来源: DEBIAN

名称: DSA-806

链接:http://www.debian.org/security/2005/dsa-806

来源: DEBIAN

名称: DSA-802

链接:http://www.debian.org/security/2005/dsa-802

来源: SECTRACK

名称: 1014857

链接:http://securitytracker.com/id?1014857

来源: SECUNIA

名称: 16765

链接:http://secunia.com/advisories/16765

来源: FREEBSD

名称: FreeBSD-SA-05:20

链接:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:20.cvsbug.asc

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享