漏洞信息详情
Info-ZIP UnZip文件名缓冲区溢出漏洞
- CNNVD编号:CNNVD-200512-812
- 危害等级: 低危
- CVE编号:
CVE-2005-4667
- 漏洞类型:
缓冲区溢出
- 发布时间:
2005-12-31
- 威胁类型:
本地
- 更新时间:
2007-10-03
- 厂 商:
info-zip - 漏洞来源:
c0ntex @gm…
-
漏洞简介
UnZip 5.50及更早版本存在缓冲区溢出,用户协助式攻击者可以通过长文件名命令行参数来执行任意代码。
漏洞公告
目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:
Info-ZIP UnZip 5.50
Debian unzip_5.50-1woody6_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_alpha.deb
Debian unzip_5.50-1woody6_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_arm.deb
Debian unzip_5.50-1woody6_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_hppa.deb
Debian unzip_5.50-1woody6_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_i386.deb
Debian unzip_5.50-1woody6_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_ia64.deb
Debian unzip_5.50-1woody6_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_m68k.deb
Debian unzip_5.50-1woody6_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_mips.deb
Debian unzip_5.50-1woody6_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_mipsel.deb
Debian unzip_5.50-1woody6_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_powerpc.deb
Debian unzip_5.50-1woody6_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_s390.deb
Debian unzip_5.50-1woody6_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.50-1woody6_sparc.deb
Mandrake unzip-5.50-9.3.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/
Mandrake unzip-5.50-9.3.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/
Mandrake unzip-5.50-9.3.M20mdk.i586.
Multi Network Firewall 2.0:
http://wwwnew.mandriva.com/en/downloads/
Mandrake unzip-5.50-9.3.M20mdk.i586.rpm
Multi Network Firewall 2.0:
http://wwwnew.mandriva.com/en/downloads/
RedHat unzip-5.50-31.1.legacy.i386.rpm
Red Hat Linux 7.3:
http://download.fedoralegacy.org/redhat/7.3/updates/i386/unzip-5.50-31.1.legacy.i386.rpm
RedHat unzip-5.50-33.1.legacy.i386.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/unzip-5.50-33.1.legacy.i386.rpm
RedHat unzip-5.50-35.1.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/unzip-5.50-35.1.legacy.i386.rpm
RedHat unzip-5.50-37.1.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/unzip-5.50-37.1.legacy.i386.rpm
Info-ZIP UnZip 5.51
Mandrake unzip-5.51-1.3.102mdk.i586.rpm
Mandriva Linux 10.2:
http://wwwnew.mandriva.com/en/downloads/
Mandrake unzip-5.51-1.3.102mdk.x86_64.rpm
Mandriva Linux 10.2:
http://wwwnew.mandriva.com/en/downloads/
RedHat unzip-5.51-4.fc3.1.legacy.i386.rpm
Fedora Core 3:
http://download.fedoralegacy.org/fedora/3/updates/i386/unzip-5.51-4.fc3.1.legacy.i386.rpm
RedHat unzip-5.51-4.fc3.1.legacy.x86_64.rpm
Fedora Core 3:
http://download.fedoralegacy.org/fedora/3/updates/x86_64/unzip-5.51-4.fc3.1.legacy.x86_64.rpm
Info-ZIP UnZip 5.52
Debian unzip_5.52-1sarge4_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4_alpha.deb
Debian unzip_5.52-1sarge4_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4_amd64.deb
Debian unzip_5.52-1sarge4_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4_arm.deb
Debian unzip_5.52-1sarge4_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/u/unzip/unzip_5.52-1sarge4_hppa.deb
Debian unzip_5.52-1sarge4_i386.deb
Debian GNU/Linux 3.1 alias sarge
参考网址
来源: UBUNTU
名称: USN-248-2
链接:http://www.ubuntulinux.org/support/documentation/usn/usn-248-2
来源: UBUNTU
名称: USN-248-1
链接:http://www.ubuntulinux.org/support/documentation/usn/usn-248-1
来源: TRUSTIX
名称: 2006-0006
链接:http://www.trustix.org/errata/2006/0006
来源: FEDORA
名称: FLSA:180159
链接:http://www.securityfocus.com/archive/1/archive/1/430300/100/0/threaded
来源: DEBIAN
名称: DSA-1012
链接:http://www.debian.org/security/2006/dsa-1012
来源: BID
名称: 15968
链接:http://www.securityfocus.com/bid/15968
来源: REDHAT
名称: RHSA-2007:0203
链接:http://www.redhat.com/support/errata/RHSA-2007-0203.html
来源: OSVDB
名称: 22400
来源: SECUNIA
名称: 25098
链接:http://secunia.com/advisories/25098
来源: FULLDISC
名称: 20051219 Unzip *ALL* verisons ;))
链接:http://archives.neohapsis.com/archives/fulldisclosure/2005-12/0930.html
来源: MANDRIVA
名称: MDKSA-2006:050
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:050