Libmusicbrainz多个缓冲区溢出漏洞

漏洞信息详情

Libmusicbrainz多个缓冲区溢出漏洞

漏洞简介

libmusicbrainz(也称mb_client或MusicBrainz Client Library) 2.1.2及早期版本,SVN 8406及早期版本中存在多个缓冲区溢出漏洞,远程攻击者可借助以下方式触发拒绝服务攻击(崩溃)或执行任意代码:(1) 该HTTP服务器的一个超长Location头,会在MBHttp::Download function in lib/http.cpp程序中引发溢出;以及(2) RDF数据中一个超长URL,如通过RDF XML文档中的rdf:resource字段中的URL,会在lib/rdfparse.c程序的很多函数中引发溢出。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Debian libmusicbrainz2-dev_2.0.2-10sarge1_alpha.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_alpha.deb

Debian libmusicbrainz2-dev_2.0.2-10sarge1_amd64.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_amd64.deb

Debian libmusicbrainz2-dev_2.0.2-10sarge1_arm.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_arm.deb

Debian libmusicbrainz2-dev_2.0.2-10sarge1_hppa.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_hppa.deb

Debian libmusicbrainz2-dev_2.0.2-10sarge1_ia64.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_ia64.deb

Debian libmusicbrainz2-dev_2.0.2-10sarge1_m68k.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_m68k.deb

Debian libmusicbrainz2-dev_2.0.2-10sarge1_mips.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_mips.deb

Debian libmusicbrainz2-dev_2.0.2-10sarge1_mipsel.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_mipsel.deb

Debian libmusicbrainz2-dev_2.0.2-10sarge1_powerpc.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_powerpc.deb

Debian libmusicbrainz2-dev_2.0.2-10sarge1_s390.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_s390.deb

Debian libmusicbrainz2-dev_2.0.2-10sarge1_sparc.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_sparc.deb

Debian libmusicbrainz2_2.0.2-10sarge1_alpha.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2_2.0.2-10sarge1_alpha.deb

Debian libmusicbrainz2_2.0.2-10sarge1_amd64.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2_2.0.2-10sarge1_amd64.deb

Debian libmusicbrainz2_2.0.2-10sarge1_arm.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2_2.0.2-10sarge1_arm.deb

Debian libmusicbrainz2_2.0.2-10sarge1_hppa.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2_2.0.2-10sarge1_hppa.deb

Debian libmusicbrainz2_2.0.2-10sarge1_ia64.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2_2.0.2-10sarge1_ia64.deb

Debian libmusicbrainz2_2.0.2-10sarge1_m68k.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2_2.0.2-10sarge1_m68k.deb

Debian libmusicbrainz2_2.0.2-10sarge1_mips.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2_2.0.2-10sarge1_mips.deb

Debian libmusicbrainz2_2.0.2-10sarge1_mipsel.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2_2.0.2-10sarge1_mipsel.deb

Debian libmusicbrainz2_2.0.2-10sarge1_powerpc.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2_2.0.2-10sarge1_powerpc.deb

Debian libmusicbrainz2_2.0.2-10sarge1_s390.deb

De

参考网址

来源: XF

名称: libmusicbrainz-rdfparse-bo(28368)

链接:http://xforce.iss.net/xforce/xfdb/28368

来源: XF

名称: libmusicbrainz-mbhttpdownload-bo(28367)

链接:http://xforce.iss.net/xforce/xfdb/28367

来源: BID

名称: 19508

链接:http://www.securityfocus.com/bid/19508

来源: BUGTRAQ

名称: 20060813 Multiple buffer-overflows in libmusicbrainz 2.1.2

链接:http://www.securityfocus.com/archive/1/archive/1/443205/100/0/threaded

来源: SECTRACK

名称: 1016691

链接:http://securitytracker.com/id?1016691

来源: SECUNIA

名称: 21404

链接:http://secunia.com/advisories/21404

来源: issues.rpath.com

链接:https://issues.rpath.com/browse/RPL-610

来源: UBUNTU

名称: USN-363

链接:http://www.ubuntu.com/usn/usn-363-1

来源: BUGTRAQ

名称: 20060830 rPSA-2006-0161-1 libmusicbrainz

链接:http://www.securityfocus.com/archive/1/archive/1/444843/100/0/threaded

来源: SUSE

名称: SUSE-SR:2006:025

链接:http://www.novell.com/linux/security/advisories/2006_25_sr.html

来源: MANDRIVA

名称: MDKSA-2006:157

链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:157

来源: DEBIAN

名称: DSA-1162

链接:http://www.debian.org/security/2006/dsa-1162

来源: SREASON

名称: 1399

链接:http://securityreason.com/securityalert/1399

来源: GENTOO

名称: GLSA-200610-09

链接:http://security.gentoo.org/glsa/glsa-200610-09.xml

来源: SECUNIA

名称: 22639

链接:http://secunia.com/advisories/22639

来源: SECUNIA

名称: 22517

链接:http://secunia.com/advisories/22517

来源: SECUNIA

名称: 22393

链接:http://secunia.com/advisories/22393

来源: SECUNIA

名称: 22191

链接:http://secunia.com/advisories/22191

来源: SECUNIA

名称: 21699

链接:http://secunia.com/advisories/21699

来源: SECUNIA

名称: 21668

链接:http://secunia.com/advisories/21668

来源: MANDRIVA

名称: MDKSA-2006:157

链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:157

来源: MISC

链接:http://aluigi.altervista.org/adv/brainzbof-adv.txt

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享