Bomberclone 多个拒绝服务攻击漏洞

漏洞信息详情

Bomberclone 多个拒绝服务攻击漏洞

漏洞简介

BomberClone 0.11.6及早期版本中,远程攻击者可借助:(1) 某畸形PKGF_ackreq信息包 – 会在pkgcache.c程序的rscache_add()函数中引发系统崩溃;及(2) 错误的信息包-客户机接收后被强制关机,并引起服务器关机,从而触发拒绝服务攻击(守护程序崩溃)。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

BomberClone BomberClone 0.11.5

Debian bomberclone-data_0.11.5-1sarge2_all.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone -data_0.11.5-1sarge2_all.deb

Debian bomberclone_0.11.5-1sarge2_alpha.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone _0.11.5-1sarge2_alpha.deb

Debian bomberclone_0.11.5-1sarge2_amd64.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone _0.11.5-1sarge2_amd64.deb

Debian bomberclone_0.11.5-1sarge2_arm.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone _0.11.5-1sarge2_arm.deb

Debian bomberclone_0.11.5-1sarge2_hppa.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone _0.11.5-1sarge2_hppa.deb

Debian bomberclone_0.11.5-1sarge2_i386.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone _0.11.5-1sarge2_i386.deb

Debian bomberclone_0.11.5-1sarge2_ia64.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone _0.11.5-1sarge2_ia64.deb

Debian bomberclone_0.11.5-1sarge2_m68k.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone _0.11.5-1sarge2_m68k.deb

Debian bomberclone_0.11.5-1sarge2_mips.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone _0.11.5-1sarge2_mips.deb

Debian bomberclone_0.11.5-1sarge2_mipsel.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone _0.11.5-1sarge2_mipsel.deb

Debian bomberclone_0.11.5-1sarge2_powerpc.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone _0.11.5-1sarge2_powerpc.deb

Debian bomberclone_0.11.5-1sarge2_s390.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone _0.11.5-1sarge2_s390.deb

Debian bomberclone_0.11.5-1sarge2_sparc.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/b/bomberclone/bomberclone _0.11.5-1sarge2_sparc.deb

参考网址

来源: XF

名称: bomberclone-error-packet-dos(28093)

链接:http://xforce.iss.net/xforce/xfdb/28093

来源: XF

名称: bomberclone-rscacheadd-dos(28090)

链接:http://xforce.iss.net/xforce/xfdb/28090

来源: BID

名称: 19255

链接:http://www.securityfocus.com/bid/19255

来源: VUPEN

名称: ADV-2006-3067

链接:http://www.frsirt.com/english/advisories/2006/3067

来源: SECUNIA

名称: 21303

链接:http://secunia.com/advisories/21303

来源: MISC

链接:http://aluigi.org/poc/bcloneboom.zip

来源: MISC

链接:http://aluigi.altervista.org/adv/bcloneboom-adv.txt

来源: OSVDB

名称: 27649

链接:http://www.osvdb.org/27649

来源: OSVDB

名称: 27647

链接:http://www.osvdb.org/27647

来源: DEBIAN

名称: DSA-1180

链接:http://www.debian.org/security/2006/dsa-1180

来源: SECUNIA

名称: 21985

链接:http://secunia.com/advisories/21985

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享