漏洞信息详情
High-Availability Linux heartbeat消息远程拒绝服务漏洞
- CNNVD编号:CNNVD-200608-271
- 危害等级: 中危
- CVE编号:
CVE-2006-3121
- 漏洞类型:
资源管理错误
- 发布时间:
2006-08-16
- 威胁类型:
远程
- 更新时间:
2006-08-31
- 厂 商:
high_availability_linux_project - 漏洞来源:
This vulnerability… -
漏洞简介
High-Availability Linux 1.2.5之前版本及2.0.7之前的2.0版本中,利用heartbeat子系统的cl_netstring.c程序的peel_netstring函数,远程攻击者可借助heartbeat消息中的长度参数触发拒绝服务攻击(崩溃)。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Linux-HA heartbeat 0.4.9 a
Linux-HA heartbeat-1.2.5.tar.gz
http://linux-ha.org/download/heartbeat-1.2.5.tar.gz
Linux-HA heartbeat 0.4.9 .1
Linux-HA heartbeat-1.2.5.tar.gz
http://linux-ha.org/download/heartbeat-1.2.5.tar.gz
Linux-HA heartbeat 0.4.9 c
Linux-HA heartbeat-1.2.5.tar.gz
http://linux-ha.org/download/heartbeat-1.2.5.tar.gz
Linux-HA heartbeat 0.4.9
Linux-HA heartbeat-1.2.5.tar.gz
http://linux-ha.org/download/heartbeat-1.2.5.tar.gz
Linux-HA heartbeat 0.4.9 b
Linux-HA heartbeat-1.2.5.tar.gz
http://linux-ha.org/download/heartbeat-1.2.5.tar.gz
Linux-HA heartbeat 0.9.4 d
Linux-HA heartbeat-1.2.5.tar.gz
http://linux-ha.org/download/heartbeat-1.2.5.tar.gz
Linux-HA heartbeat 0.9.4
Linux-HA heartbeat-1.2.5.tar.gz
http://linux-ha.org/download/heartbeat-1.2.5.tar.gz
Linux-HA heartbeat 1.2.2
Linux-HA heartbeat-1.2.5.tar.gz
http://linux-ha.org/download/heartbeat-1.2.5.tar.gz
Linux-HA heartbeat 1.2.3
Debian heartbeat-dev_1.2.3-9sarge6_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_alpha.deb
Debian heartbeat-dev_1.2.3-9sarge6_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_amd64.deb
Debian heartbeat-dev_1.2.3-9sarge6_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_arm.deb
Debian heartbeat-dev_1.2.3-9sarge6_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_hppa.deb
Debian heartbeat-dev_1.2.3-9sarge6_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_i386.deb
Debian heartbeat-dev_1.2.3-9sarge6_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_ia64.deb
Debian heartbeat-dev_1.2.3-9sarge6_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_m68k.deb
Debian heartbeat-dev_1.2.3-9sarge6_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_mips.deb
Debian heartbeat-dev_1.2.3-9sarge6_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_mipsel.deb
Debian heartbeat-dev_1.2.3-9sarge6_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_powerpc.deb
Debian heartbeat-dev_1.2.3-9sarge6_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_s390.deb
Debian heartbeat-dev_1.2.3-9sarge6_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_sparc.deb
Debian heartbeat/libpils-dev_1.2.3-9sarge6_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/heartbeat/libpils-dev_1 .2.3-9sarge6_hppa.deb
Debian heartbeat_1.2.3-9sarge6_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat_1.2 .3-9sarge6_alpha.deb
Debian heartbeat_1.2.3-9sarge6_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat_1.2 .3-9sarge6_amd64.deb
Debian heartbeat_1.2.3-9sarge6_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat_1.2 .3-9sarge6_arm.deb
Debian heartbeat_1.2.3-9sarge6_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat_1.2 .3-9sarge6_hppa.deb
Debian heartbeat_1.2.3-9sarge6_i386.deb
Debian GNU/Linux 3.1 alias sarge
参考网址
来源: BID
名称: 19516
链接:http://www.securityfocus.com/bid/19516
来源: www.linux-ha.org
链接:http://www.linux-ha.org/SecurityIssues
来源: DEBIAN
名称: DSA-1151
链接:http://www.debian.org/security/2006/dsa-1151
来源: XF
名称: heartbeat-packet-dos(28396)
链接:http://xforce.iss.net/xforce/xfdb/28396
来源: UBUNTU
名称: USN-335-1
链接:http://www.ubuntu.com/usn/usn-335-1
来源: www.linux-ha.org
链接:http://www.linux-ha.org/_cache/SecurityIssues__sec03.txt
来源: VUPEN
名称: ADV-2006-3288
链接:http://www.frsirt.com/english/advisories/2006/3288
来源: GENTOO
名称: GLSA-200608-23
链接:http://security.gentoo.org/glsa/glsa-200608-23.xml
来源: SECUNIA
名称: 21629
链接:http://secunia.com/advisories/21629
来源: SECUNIA
名称: 21521
链接:http://secunia.com/advisories/21521
来源: SECUNIA
名称: 21518
链接:http://secunia.com/advisories/21518
来源: SECUNIA
名称: 21511
链接:http://secunia.com/advisories/21511
来源: SECUNIA
名称: 21505
链接:http://secunia.com/advisories/21505
来源: MANDRIVA
名称: MDKSA-2006:142
链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:142
来源: MANDRIVA
名称: MDKSA-2006:142
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:142