cURL / libcURL TFTP URL Parser缓冲区溢出漏洞

漏洞信息详情

cURL / libcURL TFTP URL Parser缓冲区溢出漏洞

漏洞简介

在cURL and libcURL 7.15.0至7.15.2中的基于堆的缓冲区溢出,可以让远程攻击者通过带一个有效主机名和长路径的TFTP URL (tftp://)来执行任意命令。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Daniel Stenberg curl 7.15

Daniel Stenberg curl-7.15.3.zip

http://curl.haxx.se/download/curl-7.15.3.zip

RedHat Fedora curl-7.15.1-3.x86_64.rpm

Fedora Core 5

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

RedHat Fedora curl-debuginfo-7.15.1-3.ppc.rpm

Fedora Core 5

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

RedHat Fedora curl-debuginfo-7.15.1-3.x86_64.rpm

Fedora Core 5

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

RedHat Fedora curl-devel-7.15.1-3.ppc.rpm

Fedora Core 5

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

RedHat Fedora curl-devel-7.15.1-3.x86_64.rpm

Fedora Core 5

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

Daniel Stenberg curl 7.15.1

Daniel Stenberg curl-7.15.3.zip

http://curl.haxx.se/download/curl-7.15.3.zip

RedHat Fedora curl-debuginfo-7.15.1-3.i386.rpm

Fedcora Core 5:

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

RedHat Fedora curl-devel-7.15.1-3.i386.rpm

Fedcora Core 5:

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

Daniel Stenberg curl 7.15.2

Daniel Stenberg curl-7.15.3.zip

http://curl.haxx.se/download/curl-7.15.3.zip

参考网址

来源: SECUNIA

名称: 19271

链接:http://secunia.com/advisories/19271

来源: VUPEN

名称: ADV-2006-1008

链接:http://www.frsirt.com/english/advisories/2006/1008

来源: curl.haxx.se

链接:http://curl.haxx.se/docs/adv_20060320.html

来源: XF

名称: curl-tftp-bo(25318)

链接:http://xforce.iss.net/xforce/xfdb/25318

来源: TRUSTIX

名称: 2006-0016

链接:http://www.trustix.org/errata/2006/0016

来源: BID

名称: 17154

链接:http://www.securityfocus.com/bid/17154

来源: FEDORA

名称: FEDORA-2006-189

链接:http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00048.html

来源: OSVDB

名称: 23982

链接:http://www.osvdb.org/23982

来源: GENTOO

名称: GLSA-200603-19

链接:http://www.gentoo.org/security/en/glsa/glsa-200603-19.xml

来源: SECUNIA

名称: 19371

链接:http://secunia.com/advisories/19371

来源: SECUNIA

名称: 19344

链接:http://secunia.com/advisories/19344

来源: SECUNIA

名称: 19335

链接:http://secunia.com/advisories/19335

来源: FULLDISC

名称: 20060320 [SSAG#001] :: cURL tftp:// URL Buffer Overflow

链接:http://archives.neohapsis.com/archives/fulldisclosure/2006-03/1326.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享