ViewCVS Source View CRLF注入漏洞

漏洞信息详情

ViewCVS Source View CRLF注入漏洞

漏洞简介

ViewCVS 0.9.2的viewcvs存在CRLF注入漏洞,远程攻击者可以通过content-type参数中的CRLF序列注入任意HTTP标题并发起HTTP响应拆分攻击。

漏洞公告

目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:

ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/subversion-viewcvs-0.27.0-211.i586.rpm

ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/subversion-viewcvs-1.0.0-73.17.i586.rpm

ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/subversion-viewcvs-1.0.8-2.2.i586.rpm

ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/x86_64/subversion-viewcvs-1.0.8-2.2.x86_64.rpm

参考网址

来源: BID

名称: 12112

链接:http://www.securityfocus.com/bid/12112

来源: BUGTRAQ

名称: 20070226 ViewCVS 0.9.4 issues

链接:http://www.securityfocus.com/archive/1/archive/1/461382/100/0/threaded

来源: FULLDISC

名称: 20050101 Two Vulnerabilities in ViewCVS

链接:http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030514.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享