Info-ZIP UnZip文件名缓冲区溢出漏洞

漏洞信息详情

Info-ZIP UnZip文件名缓冲区溢出漏洞

漏洞简介

UnZip 5.50及更早版本存在缓冲区溢出,用户协助式攻击者可以通过长文件名命令行参数来执行任意代码。

漏洞公告

目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:

Info-ZIP UnZip 5.50

Debian unzip_5.50-1woody6_alpha.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_alpha.deb

Debian unzip_5.50-1woody6_arm.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_arm.deb

Debian unzip_5.50-1woody6_hppa.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_hppa.deb

Debian unzip_5.50-1woody6_i386.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_i386.deb

Debian unzip_5.50-1woody6_ia64.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_ia64.deb

Debian unzip_5.50-1woody6_m68k.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_m68k.deb

Debian unzip_5.50-1woody6_mips.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_mips.deb

Debian unzip_5.50-1woody6_mipsel.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_mipsel.deb

Debian unzip_5.50-1woody6_powerpc.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_powerpc.deb

Debian unzip_5.50-1woody6_s390.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_s390.deb

Debian unzip_5.50-1woody6_sparc.deb

Debian GNU/Linux 3.0 alias woody

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_sparc.deb

Mandrake unzip-5.50-9.3.C30mdk.i586.rpm

Corporate 3.0:

http://wwwnew.mandriva.com/en/downloads/

Mandrake unzip-5.50-9.3.C30mdk.x86_64.rpm

Corporate 3.0:

http://wwwnew.mandriva.com/en/downloads/

Mandrake unzip-5.50-9.3.M20mdk.i586.

Multi Network Firewall 2.0:

http://wwwnew.mandriva.com/en/downloads/

Mandrake unzip-5.50-9.3.M20mdk.i586.rpm

Multi Network Firewall 2.0:

http://wwwnew.mandriva.com/en/downloads/

RedHat unzip-5.50-31.1.legacy.i386.rpm

Red Hat Linux 7.3:

http://download.fedoralegacy.org/redhat/7.3/updates/i386/unzip-5.50-31.1.legacy.i386.rpm

RedHat unzip-5.50-33.1.legacy.i386.rpm

Red Hat Linux 9:

http://download.fedoralegacy.org/redhat/9/updates/i386/unzip-5.50-33.1.legacy.i386.rpm

RedHat unzip-5.50-35.1.legacy.i386.rpm

Fedora Core 1:

http://download.fedoralegacy.org/fedora/1/updates/i386/unzip-5.50-35.1.legacy.i386.rpm

RedHat unzip-5.50-37.1.legacy.i386.rpm

Fedora Core 2:

http://download.fedoralegacy.org/fedora/2/updates/i386/unzip-5.50-37.1.legacy.i386.rpm

Info-ZIP UnZip 5.51

Mandrake unzip-5.51-1.3.102mdk.i586.rpm

Mandriva Linux 10.2:

http://wwwnew.mandriva.com/en/downloads/

Mandrake unzip-5.51-1.3.102mdk.x86_64.rpm

Mandriva Linux 10.2:

http://wwwnew.mandriva.com/en/downloads/

RedHat unzip-5.51-4.fc3.1.legacy.i386.rpm

Fedora Core 3:

http://download.fedoralegacy.org/fedora/3/updates/i386/unzip-5.51-4.fc3.1.legacy.i386.rpm

RedHat unzip-5.51-4.fc3.1.legacy.x86_64.rpm

Fedora Core 3:

http://download.fedoralegacy.org/fedora/3/updates/x86_64/unzip-5.51-4.fc3.1.legacy.x86_64.rpm

Info-ZIP UnZip 5.52

Debian unzip_5.52-1sarge4_alpha.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4_alpha.deb

Debian unzip_5.52-1sarge4_amd64.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4_amd64.deb

Debian unzip_5.52-1sarge4_arm.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4_arm.deb

Debian unzip_5.52-1sarge4_hppa.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4_hppa.deb

Debian unzip_5.52-1sarge4_i386.deb

Debian GNU/Linux 3.1 alias sarge

http://security.deb

参考网址

来源: UBUNTU

名称: USN-248-2

链接:http://www.ubuntulinux.org/support/documentation/usn/usn-248-2

来源: UBUNTU

名称: USN-248-1

链接:http://www.ubuntulinux.org/support/documentation/usn/usn-248-1

来源: TRUSTIX

名称: 2006-0006

链接:http://www.trustix.org/errata/2006/0006

来源: FEDORA

名称: FLSA:180159

链接:http://www.securityfocus.com/archive/1/archive/1/430300/100/0/threaded

来源: DEBIAN

名称: DSA-1012

链接:http://www.debian.org/security/2006/dsa-1012

来源: BID

名称: 15968

链接:http://www.securityfocus.com/bid/15968

来源: REDHAT

名称: RHSA-2007:0203

链接:http://www.redhat.com/support/errata/RHSA-2007-0203.html

来源: OSVDB

名称: 22400

链接:http://www.osvdb.org/22400

来源: SECUNIA

名称: 25098

链接:http://secunia.com/advisories/25098

来源: FULLDISC

名称: 20051219 Unzip *ALL* verisons ;))

链接:http://archives.neohapsis.com/archives/fulldisclosure/2005-12/0930.html

来源: MANDRIVA

名称: MDKSA-2006:050

链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:050

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享