CGI:IRC Client.C 多个远程缓冲区溢出漏洞

漏洞信息详情

CGI:IRC Client.C 多个远程缓冲区溢出漏洞

漏洞简介

CGI:IRC (CGIIRC) 0.5.8 之前版本的client.c中存在多个缓冲区溢出。远程攻击者可以借助(1) cookies或(2) 查询字符串,执行任意代码。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

CGI:IRC CGI:IRC 0.5.4

Debian cgiirc_0.5.4-6sarge1_alpha.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/c/cgiirc/cgiirc_0.5.4-6sa

rge1_alpha.deb

Debian cgiirc_0.5.4-6sarge1_amd64.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/c/cgiirc/cgiirc_0.5.4-6sa

rge1_amd64.deb

Debian cgiirc_0.5.4-6sarge1_arm.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/c/cgiirc/cgiirc_0.5.4-6sa

rge1_arm.deb

Debian cgiirc_0.5.4-6sarge1_hppa.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/c/cgiirc/cgiirc_0.5.4-6sa

rge1_hppa.deb

Debian cgiirc_0.5.4-6sarge1_i386.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/c/cgiirc/cgiirc_0.5.4-6sa

rge1_i386.deb

Debian cgiirc_0.5.4-6sarge1_ia64.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/c/cgiirc/cgiirc_0.5.4-6sa

rge1_ia64.deb

Debian cgiirc_0.5.4-6sarge1_m68k.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/c/cgiirc/cgiirc_0.5.4-6sa

rge1_m68k.deb

Debian cgiirc_0.5.4-6sarge1_mips.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/c/cgiirc/cgiirc_0.5.4-6sa

rge1_mips.deb

Debian cgiirc_0.5.4-6sarge1_mipsel.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/c/cgiirc/cgiirc_0.5.4-6sa

rge1_mipsel.deb

Debian cgiirc_0.5.4-6sarge1_powerpc.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/c/cgiirc/cgiirc_0.5.4-6sa

rge1_powerpc.deb

Debian cgiirc_0.5.4-6sarge1_s390.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/c/cgiirc/cgiirc_0.5.4-6sa

rge1_s390.deb

Debian cgiirc_0.5.4-6sarge1_sparc.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/c/cgiirc/cgiirc_0.5.4-6sa

rge1_sparc.deb

参考网址

来源: VUPEN

名称: ADV-2006-1607

链接:http://www.frsirt.com/english/advisories/2006/1607

来源: SECUNIA

名称: 19922

链接:http://secunia.com/advisories/19922

来源: cvs.cgiirc.org

链接:http://cvs.cgiirc.org/chngview?cn=263

来源: cvs.cgiirc.org

链接:http://cvs.cgiirc.org/timeline?d=300&e=2006-Apr-30&c=2&px=&s=0&dm=1&x=1&m=1

来源: cvs.cgiirc.org

链接:http://cvs.cgiirc.org/chngview?cn=283

来源: bugs.debian.org

链接:http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=365680

来源: XF

名称: cgiirc-client-bo(26173)

链接:http://xforce.iss.net/xforce/xfdb/26173

来源: BID

名称: 17799

链接:http://www.securityfocus.com/bid/17799

来源: DEBIAN

名称: DSA-1052

链接:http://www.debian.org/security/2006/dsa-1052

来源: SECUNIA

名称: 19985

链接:http://secunia.com/advisories/19985

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享