漏洞信息详情
多个厂商ReadDir_R缓冲区溢出漏洞
- CNNVD编号:CNNVD-200512-989
- 危害等级: 中危
- CVE编号:
CVE-2005-4784
- 漏洞类型:
缓冲区溢出
- 发布时间:
2005-12-31
- 威胁类型:
本地
- 更新时间:
2006-04-28
- 厂 商:
austin_group - 漏洞来源:
Ben Hutchings
-
漏洞简介
在多个包中使用时,POSIX readdir_r函数存在多个缓冲区溢出,本地用户可以通过(1)利用在opendir和pathcon调用之间的竞态条件的symlink攻击并变更文件系统为一个带有更大最大directtory-entry名字长度的系统,或(2)可能通过程序员引入的有关带有小结构指向的操作系统的错误,如Solaris或BeOS, 发起拒绝服务并可能执行任意代码,如在这些包中,包括(a)gcj,(b)KDE,(c)libwww,(d)Rudiments库,(e)teTeX,(f)xmail,(g)bfbtester,(h)ncftp,(i)netwib,(j)OpenOffice.org,(k)Pike,(l)reprepro,(m)Tcl和(n)xgsmlib。
漏洞公告
参考网址
来源: BID
名称: 15259
链接:http://www.securityfocus.com/bid/15259
来源: BUGTRAQ
名称: 20051108 Re: readdir_r considered harmful
链接:http://www.securityfocus.com/archive/1/416048/30/0/threaded
来源: BUGTRAQ
名称: 20051106 Re: readdir_r considered harmful
链接:http://www.securityfocus.com/archive/1/416002/30/0/threaded
来源: BUGTRAQ
名称: 20051106 Re: readdir_r considered harmful
链接:http://www.securityfocus.com/archive/1/415999/30/0/threaded
来源: BUGTRAQ
名称: 20051106 Re: readdir_r considered harmful
链接:http://www.securityfocus.com/archive/1/415998/30/0/threaded
来源: BUGTRAQ
名称: 20051105 Re: readdir_r considered harmful
链接:http://www.securityfocus.com/archive/1/415995/30/0/threaded
来源: BUGTRAQ
名称: 20051105 Re: readdir_r considered harmful
链接:http://www.securityfocus.com/archive/1/415790/30/0/threaded
来源: BUGTRAQ
名称: 20051101 readdir_r considered harmful
链接:http://www.securityfocus.com/archive/1/415781
来源: MISC
链接:http://womble.decadentplace.org.uk/readdir_r-advisory.html