漏洞信息详情
Cheese Tracker ‘loader_xm.cpp’ XM Loader缓冲区溢出漏洞
- CNNVD编号:CNNVD-200607-440
- 危害等级: 中危
- CVE编号:
CVE-2006-3814
- 漏洞类型:
缓冲区溢出
- 发布时间:
2006-07-25
- 威胁类型:
远程
- 更新时间:
2006-08-07
- 厂 商:
cheese_tracker - 漏洞来源:
Luigi Auriemma dis… -
漏洞简介
Cheese Tracker 0.9.9及之前版本的loader_xm.cpp中的Loader_XM::load_instrument_internal函数存在缓冲区溢出。用户协助式攻击者可以借助带有大量附加数据的特制文件,执行任意代码。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Cheese Tracker Cheese Tracker 0.9.9
Debian cheesetracker_0.9.9-1sarge1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/cheesetracker/cheesetra cker_0.9.9-1sarge1_alpha.deb
Debian cheesetracker_0.9.9-1sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/cheesetracker/cheesetra cker_0.9.9-1sarge1_amd64.deb
Debian cheesetracker_0.9.9-1sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/cheesetracker/cheesetra cker_0.9.9-1sarge1_arm.deb
Debian cheesetracker_0.9.9-1sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/cheesetracker/cheesetra cker_0.9.9-1sarge1_hppa.deb
Debian cheesetracker_0.9.9-1sarge1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/cheesetracker/cheesetra cker_0.9.9-1sarge1_i386.deb
Debian cheesetracker_0.9.9-1sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/cheesetracker/cheesetra cker_0.9.9-1sarge1_ia64.deb
Debian cheesetracker_0.9.9-1sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/cheesetracker/cheesetra cker_0.9.9-1sarge1_m68k.deb
Debian cheesetracker_0.9.9-1sarge1_mips.deb
Debian 3.1 (stable)
http://security.debian.org/pool/updates/main/c/cheesetracker/cheesetra cker_0.9.9-1sarge1_mips.deb
Debian cheesetracker_0.9.9-1sarge1_mipsel.deb
Debian 3.1 (stable)
http://security.debian.org/pool/updates/main/c/cheesetracker/cheesetra cker_0.9.9-1sarge1_mipsel.deb
Debian cheesetracker_0.9.9-1sarge1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/cheesetracker/cheesetra cker_0.9.9-1sarge1_powerpc.deb
Debian cheesetracker_0.9.9-1sarge1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/cheesetracker/cheesetra cker_0.9.9-1sarge1_s390.deb
Debian cheesetracker_0.9.9-1sarge1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/c/cheesetracker/cheesetra cker_0.9.9-1sarge1_sparc.deb
参考网址
来源: XF
名称: cheesetronic-loaderxm-bo(27957)
链接:http://xforce.iss.net/xforce/xfdb/27957
来源: BID
名称: 19115
链接:http://www.securityfocus.com/bid/19115
来源: BUGTRAQ
名称: 20060723 Buffer-overflow in the XM loader of Cheese Tracker 0.9.9
链接:http://www.securityfocus.com/archive/1/archive/1/440962/100/0/threaded
来源: MISC
链接:http://aluigi.altervista.org/adv/cheesebof-adv.txt
来源: GENTOO
名称: GLSA-200610-13
链接:http://www.gentoo.org/security/en/glsa/glsa-200610-13.xml
来源: DEBIAN
名称: DSA-1166
链接:http://www.debian.org/security/2006/dsa-1166
来源: SREASON
名称: 1291
链接:http://securityreason.com/securityalert/1291
来源: SECUNIA
名称: 22643
链接:http://secunia.com/advisories/22643
来源: SECUNIA
名称: 21759