漏洞信息详情
mpg321 MP3 文件远程格式字符串漏洞
漏洞简介
mpg321 0.2.10版本存在漏洞。远程攻击者可能通过传递某些字符串到printf函数的mp3文件执行任意代码,可能触发格式字符串漏洞。
漏洞公告
Debian has released advisory DSA 411-1 to address this issue. Please see the attached advisory for details on obtaining and applying fixes. Gentoo Linux has released advisory GLSA 200503-34 dealing with this issue. Gentoo advises that all users carry out the following commands with superuser privileges to update their packages: emerge --sync emerge --ask --oneshot --verbose ">=media-sound/mpg321-0.2.10-r2" For more information, please see the referenced Gentoo linux advisory. mpg321 mpg321 0.2.10
- Debian mpg321_0.2.10.2_alpha.debDebian GNU/Linux 3.0 alias woody. http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ alpha.deb
- Debian mpg321_0.2.10.2_arm.debDebian GNU/Linux 3.0 alias woody. http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ arm.deb
- Debian mpg321_0.2.10.2_hppa.debDebian GNU/Linux 3.0 alias woody. http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ hppa.deb
- Debian mpg321_0.2.10.2_i386.debDebian GNU/Linux 3.0 alias woody. http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ i386.deb
- Debian mpg321_0.2.10.2_ia64.debDebian GNU/Linux 3.0 alias woody. http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ ia64.deb
- Debian mpg321_0.2.10.2_m68k.debDebian GNU/Linux 3.0 alias woody. http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ m68k.deb
- Debian mpg321_0.2.10.2_mips.debDebian GNU/Linux 3.0 alias woody. http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ mips.deb
- Debian mpg321_0.2.10.2_mipsel.debDebian GNU/Linux 3.0 alias woody. http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ mipsel.deb
- Debian mpg321_0.2.10.2_powerpc.debDebian GNU/Linux 3.0 alias woody. http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ powerpc.deb
- Debian mpg321_0.2.10.2_s390.debDebian GNU/Linux 3.0 alias woody. http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ s390.deb
- Debian mpg321_0.2.10.2_sparc.debDebian GNU/Linux 3.0 alias woody. http://security.debian.org/pool/updates/main/m/mpg321/mpg321_0.2.10.2_ sparc.deb
参考网址
来源: XF 名称: mpg321-mp3-format-string(14148) 链接:http://xforce.iss.net/xforce/xfdb/14148 来源: BID 名称: 9364 链接:http://www.securityfocus.com/bid/9364 来源: OSVDB 名称: 3331 链接:http://www.osvdb.org/3331 来源: SUSE 名称: SuSE-SA:2004:002 链接:http://www.novell.com/linux/security/advisories/2004_02_tcpdump.html 来源: DEBIAN 名称: DSA-411 链接:http://www.debian.org/security/2004/dsa-411
受影响实体
- Mpg321 Mpg321:0.2.10<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...