漏洞信息详情
Libmusicbrainz多个缓冲区溢出漏洞
- CNNVD编号:CNNVD-200608-281
- 危害等级: 高危
- CVE编号:
CVE-2006-4197
- 漏洞类型:
缓冲区溢出
- 发布时间:
2006-08-17
- 威胁类型:
远程
- 更新时间:
2006-08-24
- 厂 商:
musicbrainz - 漏洞来源:
Luigi Auriemma is … -
漏洞简介
libmusicbrainz(也称mb_client或MusicBrainz Client Library) 2.1.2及早期版本,SVN 8406及早期版本中存在多个缓冲区溢出漏洞,远程攻击者可借助以下方式触发拒绝服务攻击(崩溃)或执行任意代码:(1) 该HTTP服务器的一个超长Location头,会在MBHttp::Download function in lib/http.cpp程序中引发溢出;以及(2) RDF数据中一个超长URL,如通过RDF XML文档中的rdf:resource字段中的URL,会在lib/rdfparse.c程序的很多函数中引发溢出。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Debian libmusicbrainz2-dev_2.0.2-10sarge1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_alpha.deb
Debian libmusicbrainz2-dev_2.0.2-10sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_amd64.deb
Debian libmusicbrainz2-dev_2.0.2-10sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_arm.deb
Debian libmusicbrainz2-dev_2.0.2-10sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_hppa.deb
Debian libmusicbrainz2-dev_2.0.2-10sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_ia64.deb
Debian libmusicbrainz2-dev_2.0.2-10sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_m68k.deb
Debian libmusicbrainz2-dev_2.0.2-10sarge1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_mips.deb
Debian libmusicbrainz2-dev_2.0.2-10sarge1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_mipsel.deb
Debian libmusicbrainz2-dev_2.0.2-10sarge1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_powerpc.deb
Debian libmusicbrainz2-dev_2.0.2-10sarge1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_s390.deb
Debian libmusicbrainz2-dev_2.0.2-10sarge1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2-dev_2.0.2-10sarge1_sparc.deb
Debian libmusicbrainz2_2.0.2-10sarge1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2_2.0.2-10sarge1_alpha.deb
Debian libmusicbrainz2_2.0.2-10sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2_2.0.2-10sarge1_amd64.deb
Debian libmusicbrainz2_2.0.2-10sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2_2.0.2-10sarge1_arm.deb
Debian libmusicbrainz2_2.0.2-10sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2_2.0.2-10sarge1_hppa.deb
Debian libmusicbrainz2_2.0.2-10sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2_2.0.2-10sarge1_ia64.deb
Debian libmusicbrainz2_2.0.2-10sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2_2.0.2-10sarge1_m68k.deb
Debian libmusicbrainz2_2.0.2-10sarge1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2_2.0.2-10sarge1_mips.deb
Debian libmusicbrainz2_2.0.2-10sarge1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2_2.0.2-10sarge1_mipsel.deb
Debian libmusicbrainz2_2.0.2-10sarge1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libm/libmusicbrainz-2.0/l ibmusicbrainz2_2.0.2-10sarge1_powerpc.deb
Debian libmusicbrainz2_2.0.2-10sarge1_s390.deb
De
参考网址
来源: XF
名称: libmusicbrainz-rdfparse-bo(28368)
链接:http://xforce.iss.net/xforce/xfdb/28368
来源: XF
名称: libmusicbrainz-mbhttpdownload-bo(28367)
链接:http://xforce.iss.net/xforce/xfdb/28367
来源: BID
名称: 19508
链接:http://www.securityfocus.com/bid/19508
来源: BUGTRAQ
名称: 20060813 Multiple buffer-overflows in libmusicbrainz 2.1.2
链接:http://www.securityfocus.com/archive/1/archive/1/443205/100/0/threaded
来源: SECTRACK
名称: 1016691
链接:http://securitytracker.com/id?1016691
来源: SECUNIA
名称: 21404
链接:http://secunia.com/advisories/21404
来源: issues.rpath.com
链接:https://issues.rpath.com/browse/RPL-610
来源: UBUNTU
名称: USN-363
链接:http://www.ubuntu.com/usn/usn-363-1
来源: BUGTRAQ
名称: 20060830 rPSA-2006-0161-1 libmusicbrainz
链接:http://www.securityfocus.com/archive/1/archive/1/444843/100/0/threaded
来源: SUSE
名称: SUSE-SR:2006:025
链接:http://www.novell.com/linux/security/advisories/2006_25_sr.html
来源: MANDRIVA
名称: MDKSA-2006:157
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:157
来源: DEBIAN
名称: DSA-1162
链接:http://www.debian.org/security/2006/dsa-1162
来源: SREASON
名称: 1399
链接:http://securityreason.com/securityalert/1399
来源: GENTOO
名称: GLSA-200610-09
链接:http://security.gentoo.org/glsa/glsa-200610-09.xml
来源: SECUNIA
名称: 22639
链接:http://secunia.com/advisories/22639
来源: SECUNIA
名称: 22517
链接:http://secunia.com/advisories/22517
来源: SECUNIA
名称: 22393
链接:http://secunia.com/advisories/22393
来源: SECUNIA
名称: 22191
链接:http://secunia.com/advisories/22191
来源: SECUNIA
名称: 21699
链接:http://secunia.com/advisories/21699
来源: SECUNIA
名称: 21668
链接:http://secunia.com/advisories/21668
来源: MANDRIVA
名称: MDKSA-2006:157
链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:157
来源: MISC