ClamAV Popen Function 远程代码执行漏洞

漏洞信息详情

ClamAV Popen Function 远程代码执行漏洞

漏洞简介

ClamAV版本之前的版本0.91.2版本的clamav-milter,当在black hole mode中运行时,远程攻击者可以借助在某popen调用程序中的外壳元字符,且这些元字符涉及sendmail字段的获取\”,以执行任意指令。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Clam Anti-Virus ClamAV 0.88.6

Clam Anti-Virus clamav-0.91.2.tar.gz


http://downloads.sourceforge.net/clamav/clamav-0.91.2.tar.gz?modtime=1187690903&big_mirror=0“>


http://downloads.sourceforge.net/clamav/clamav-0.91.2.tar.gz?modtime=1


187690903&big_mirror=0

Clam Anti-Virus ClamAV 0.51

Clam Anti-Virus ClamAV 0.53

Clam Anti-Virus ClamAV 0.65

Clam Anti-Virus ClamAV 0.70

Clam Anti-Virus ClamAV 0.75.1

Clam Anti-Virus ClamAV 0.80 rc4

Clam Anti-Virus ClamAV 0.80

Clam Anti-Virus ClamAV 0.80 rc3

Clam Anti-Virus ClamAV 0.80 rc1

Clam Anti-Virus ClamAV 0.81

Clam Anti-Virus ClamAV 0.82

Clam Anti-Virus ClamAV 0.83

Clam Anti-Virus ClamAV 0.84

参考网址

来源: BID

名称: 25439

链接:http://www.securityfocus.com/bid/25439

来源: MISC

链接:http://www.nruns.com/security_advisory_clamav_remote_code_exection.php

来源: FEDORA

名称: FEDORA-2007-2050

链接:https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00104.html

来源: TRUSTIX

名称: 2007-0026

链接:http://www.trustix.org/errata/2007/0026/

来源: SECTRACK

名称: 1018610

链接:http://www.securitytracker.com/id?1018610

来源: BUGTRAQ

名称: 20070824 n.runs-SA-2007.025 – ClamAV Remote Code Execution Advisory

链接:http://www.securityfocus.com/archive/1/archive/1/477723/100/0/threaded

来源: SUSE

名称: SUSE-SR:2007:018

链接:http://www.novell.com/linux/security/advisories/2007_18_sr.html

来源: MANDRIVA

名称: MDKSA-2007:172

链接:http://www.mandriva.com/security/advisories?name=MDKSA-2007:172

来源: DEBIAN

名称: DSA-1366

链接:http://www.debian.org/security/2007/dsa-1366

来源: SREASON

名称: 3063

链接:http://securityreason.com/securityalert/3063

来源: GENTOO

名称: GLSA-200709-14

链接:http://security.gentoo.org/glsa/glsa-200709-14.xml

来源: SECUNIA

名称: 26916

链接:http://secunia.com/advisories/26916

来源: SECUNIA

名称: 26822

链接:http://secunia.com/advisories/26822

来源: SECUNIA

名称: 26751

链接:http://secunia.com/advisories/26751

来源: SECUNIA

名称: 26683

链接:http://secunia.com/advisories/26683

来源: SECUNIA

名称: 26674

链接:http://secunia.com/advisories/26674

来源: SECUNIA

名称: 26654

链接:http://secunia.com/advisories/26654

来源: VUPEN

名称: ADV-2008-0924

链接:http://www.frsirt.com/english/advisories/2008/0924/references

来源: SECUNIA

名称: 29420

链接:http://secunia.com/advisories/29420

来源: APPLE

名称: APPLE-SA-2008-03-18

链接:http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html

来源: docs.info.apple.com

链接:http://docs.info.apple.com/article.html?artnum=307562

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享