Debian GNU/Linux Telnetd非法内存处理漏洞
2008-04-09 04:20:39来源:互联网 阅读 ()
发布日期:2004-10-03
更新日期:2004-10-08
受影响系统:
Debian telnetd 0.17-25不受影响系统:
Debian telnetd 0.17-18
Debian telnetd 0.17-26描述:
Debian telnetd 0.17-18woody1
BUGTRAQ ID: 11313
CVE(CAN) ID: CVE-2004-0911
Debian是一款开放源代码的LINUX系统。
Debian的telnetd存在一个非法内存处理问题,远程攻击者可以利用这个漏洞以进程权限在系统上执行任意指令。
Debian Linux中的Netkit telnetd实现缺少AYT漏洞补丁,此漏洞由于没有正确分配和释放内存缓冲区,可导致以telnetd进程权限执行任意指令。
<*来源:Michal Zalewski (lcamtuf@echelon.pl)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=109571642600015&w=2
http://www.debian.org/security/2002/dsa-556
*>
建议:
厂商补丁:
Debian
------
Debian已经为此发布了一个安全公告(DSA-556-1)以及相应补丁:
DSA-556-1:New netkit-telnet packages fix invalid free
链接:http://www.debian.org/security/2002/dsa-556
补丁下载:
Source archives:
http://security.debian.org/pool/updates/main/n/netkit-telnet/netkit-telnet_0.17-18woody1.dsc
Size/MD5 checksum: 602 9b997bc6951c08c4f22c29dfe8fd6cfb
http://security.debian.org/pool/updates/main/n/netkit-telnet/netkit-telnet_0.17-18woody1.diff.gz
Size/MD5 checksum: 22010 29a22dc590270539e60e040fe33678a3
http://security.debian.org/pool/updates/main/n/netkit-telnet/netkit-telnet_0.17.orig.tar.gz
Size/MD5 checksum: 133749 d6beabaaf53fe6e382c42ce3faa05a36
Alpha architecture:
http://security.debian.org/pool/updates/main/n/netkit-telnet/telnet_0.17-18woody1_alpha.deb
Size/MD5 checksum: 84080 64e59060bcc7713c33051b129eb7a7b2
http://security.debian.org/pool/updates/main/n/netkit-telnet/telnetd_0.17-18woody1_alpha.deb
Size/MD5 checksum: 45712 dc1f4eba203e25e0e69fde84d0c68deb
ARM architecture:
http://security.debian.org/pool/updates/main/n/netkit-telnet/telnet_0.17-18woody1_arm.deb
Size/MD5 checksum: 69840 cee0940a812e1c14b3541bd408d8e772
http://security.debian.org/pool/updates/main/n/netkit-telnet/telnetd_0.17-18woody1_arm.deb
Size/MD5 checksum: 39534 78a51c224f171e029799183b8ba42357
Intel IA-32 architecture:
http://security.debian.org/pool/updates/main/n/netkit-telnet/telnet_0.17-18woody1_i386.deb
Size/MD5 checksum: 70668 8f16858a8702fa7840c60fa272f336b5
http://security.debian.org/pool/updates/main/n/netkit-telnet/telnetd_0.17-18woody1_i386.deb
Size/MD5 checksum: 37344 48eadf90962f7641c9b109e6ed0b31e4
Intel IA-64 architecture:
http://security.debian.org/pool/updates/main/n/netkit-telnet/telnet_0.17-18woody1_ia64.deb
Size/MD5 checksum: 102662 7ba021e10ae96097686b70c2b29c281d
http://security.debian.org/pool/updates/main/n/netkit-telnet/telnetd_0.17-18woody1_ia64.deb
Size/MD5 checksum: 52356 a87e16a648e472e06c0bcacdee2a3465
HP Precision architecture:
http://security.debian.org/pool/updates/main/n/netkit-telnet/telnet_0.17-18woody1_hppa.deb
Size/MD5 checksum: 69878 436ca10d3adf53cf95d0fb1532fe8ca4
http://security.debian.org/pool/updates/main/n/netkit-telnet/telnetd_0.17-18woody1_hppa.deb
Size/MD5 checksum: 43430 f782d2555aba39ac4a3fc375601cbe41
Motorola 680x0 architecture:
http://security.debian.org/pool/updates/main/n/netkit-telnet/telnet_0.17-18woody1_m68k.deb
Size/MD5 checksum: 67062 53604751760b712a28141bbfea772f02
http://security.debian.org/pool/updates/main/n/netkit-telnet/telnetd_0.17-18woody1_m68k.deb
Size/MD5 checksum: 37350 b8ba70a9e2b9c94edfbc2d5ad482f5f5
Big endian MIPS architecture:
http://security.debian.org/pool/updates/main/n/netkit-telnet/telnet_0.17-18woody1_mips.deb
Size/MD5 checksum: 80782 34f5870ce7c7e90a7337e4ace622c145
http://security.debian.org/pool/updates/main/n/netkit-telnet/telnetd_0.17-18woody1_mips.deb
Size/MD5 checksum: 42520 005a24828fe4c192cbcaaa1b9e4a4b09
Little endian MIPS architecture:
http://security.debian.org/pool/updates/main/n/netkit-telnet/telnet_0.17-18woody1_mipsel.deb
Size/MD5 checksum: 80670 b9cea5d2edda4f8c9453789c27aae058
http://security.debian.org/pool/updates/main/n/netkit-telnet/telnetd_0.17-18woody1_mipsel.deb
Size/MD5 checksum: 42490 cdb8fbe3737a45b2d215d36f8952c6ee
PowerPC architecture:
http://security.debian.org/pool/updates/main/n/netkit-telnet/telnet_0.17-18woody1_powerpc.deb
Size/MD5 checksum: 73142 0f784e76f7d00238a9e9b13b880682db
http://security.debian.org/pool/updates/main/n/netkit-telnet/telnetd_0.17-18woody1_powerpc.deb
标签:
版权申明:本站文章部分自网络,如有侵权,请联系:west999com@outlook.com
特别注意:本站所有转载文章言论不代表本站观点,本站所提供的摄影照片,插画,设计作品,如需使用,请与原作者联系,版权归原作者所有
IDC资讯: 主机资讯 注册资讯 托管资讯 vps资讯 网站建设
网站运营: 建站经验 策划盈利 搜索优化 网站推广 免费资源
网络编程: Asp.Net编程 Asp编程 Php编程 Xml编程 Access Mssql Mysql 其它
服务器技术: Web服务器 Ftp服务器 Mail服务器 Dns服务器 安全防护
软件技巧: 其它软件 Word Excel Powerpoint Ghost Vista QQ空间 QQ FlashGet 迅雷
网页制作: FrontPages Dreamweaver Javascript css photoshop fireworks Flash