High-Availability Linux heartbeat消息远程拒绝服务漏洞

漏洞信息详情

High-Availability Linux heartbeat消息远程拒绝服务漏洞

漏洞简介

High-Availability Linux 1.2.5之前版本及2.0.7之前的2.0版本中,利用heartbeat子系统的cl_netstring.c程序的peel_netstring函数,远程攻击者可借助heartbeat消息中的长度参数触发拒绝服务攻击(崩溃)。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Linux-HA heartbeat 0.4.9 a

Linux-HA heartbeat-1.2.5.tar.gz

http://linux-ha.org/download/heartbeat-1.2.5.tar.gz

Linux-HA heartbeat 0.4.9 .1

Linux-HA heartbeat-1.2.5.tar.gz

http://linux-ha.org/download/heartbeat-1.2.5.tar.gz

Linux-HA heartbeat 0.4.9 c

Linux-HA heartbeat-1.2.5.tar.gz

http://linux-ha.org/download/heartbeat-1.2.5.tar.gz

Linux-HA heartbeat 0.4.9

Linux-HA heartbeat-1.2.5.tar.gz

http://linux-ha.org/download/heartbeat-1.2.5.tar.gz

Linux-HA heartbeat 0.4.9 b

Linux-HA heartbeat-1.2.5.tar.gz

http://linux-ha.org/download/heartbeat-1.2.5.tar.gz

Linux-HA heartbeat 0.9.4 d

Linux-HA heartbeat-1.2.5.tar.gz

http://linux-ha.org/download/heartbeat-1.2.5.tar.gz

Linux-HA heartbeat 0.9.4

Linux-HA heartbeat-1.2.5.tar.gz

http://linux-ha.org/download/heartbeat-1.2.5.tar.gz

Linux-HA heartbeat 1.2.2

Linux-HA heartbeat-1.2.5.tar.gz

http://linux-ha.org/download/heartbeat-1.2.5.tar.gz

Linux-HA heartbeat 1.2.3

Debian heartbeat-dev_1.2.3-9sarge6_alpha.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_alpha.deb

Debian heartbeat-dev_1.2.3-9sarge6_amd64.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_amd64.deb

Debian heartbeat-dev_1.2.3-9sarge6_arm.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_arm.deb

Debian heartbeat-dev_1.2.3-9sarge6_hppa.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_hppa.deb

Debian heartbeat-dev_1.2.3-9sarge6_i386.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_i386.deb

Debian heartbeat-dev_1.2.3-9sarge6_ia64.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_ia64.deb

Debian heartbeat-dev_1.2.3-9sarge6_m68k.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_m68k.deb

Debian heartbeat-dev_1.2.3-9sarge6_mips.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_mips.deb

Debian heartbeat-dev_1.2.3-9sarge6_mipsel.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_mipsel.deb

Debian heartbeat-dev_1.2.3-9sarge6_powerpc.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_powerpc.deb

Debian heartbeat-dev_1.2.3-9sarge6_s390.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_s390.deb

Debian heartbeat-dev_1.2.3-9sarge6_sparc.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat-dev _1.2.3-9sarge6_sparc.deb

Debian heartbeat/libpils-dev_1.2.3-9sarge6_hppa.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/heartbeat/libpils-dev_1 .2.3-9sarge6_hppa.deb

Debian heartbeat_1.2.3-9sarge6_alpha.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat_1.2 .3-9sarge6_alpha.deb

Debian heartbeat_1.2.3-9sarge6_amd64.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat_1.2 .3-9sarge6_amd64.deb

Debian heartbeat_1.2.3-9sarge6_arm.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat_1.2 .3-9sarge6_arm.deb

Debian heartbeat_1.2.3-9sarge6_hppa.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/heartbeat/heartbeat_1.2 .3-9sarge6_hppa.deb

Debian heartbeat_1.2.3-9sarge6_i386.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updat

参考网址

来源: BID

名称: 19516

链接:http://www.securityfocus.com/bid/19516

来源: www.linux-ha.org

链接:http://www.linux-ha.org/SecurityIssues

来源: DEBIAN

名称: DSA-1151

链接:http://www.debian.org/security/2006/dsa-1151

来源: XF

名称: heartbeat-packet-dos(28396)

链接:http://xforce.iss.net/xforce/xfdb/28396

来源: UBUNTU

名称: USN-335-1

链接:http://www.ubuntu.com/usn/usn-335-1

来源: www.linux-ha.org

链接:http://www.linux-ha.org/_cache/SecurityIssues__sec03.txt

来源: VUPEN

名称: ADV-2006-3288

链接:http://www.frsirt.com/english/advisories/2006/3288

来源: GENTOO

名称: GLSA-200608-23

链接:http://security.gentoo.org/glsa/glsa-200608-23.xml

来源: SECUNIA

名称: 21629

链接:http://secunia.com/advisories/21629

来源: SECUNIA

名称: 21521

链接:http://secunia.com/advisories/21521

来源: SECUNIA

名称: 21518

链接:http://secunia.com/advisories/21518

来源: SECUNIA

名称: 21511

链接:http://secunia.com/advisories/21511

来源: SECUNIA

名称: 21505

链接:http://secunia.com/advisories/21505

来源: MANDRIVA

名称: MDKSA-2006:142

链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:142

来源: MANDRIVA

名称: MDKSA-2006:142

链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:142

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享