漏洞信息详情
LM_sensors PWMConfig 不安全临时文件创建漏洞
漏洞简介
LM_sensors 2.9.1之前的版本中的pwmconfig以不安全的方式创建临时文件。这使得本地用户可以借助于对临时文件fancontrol的符号链接攻击重写任意文件。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
lm_sensors lm_sensors 2.8.4
Mandriva liblm_sensors3-2.8.4-2.1.100mdk.i586.rpm
Mandrakelinux 10.0
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva liblm_sensors3-2.8.4-2.1.C30mdk.i586.rpm
Corporate 3.0
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva liblm_sensors3-devel-2.8.4-2.1.100mdk.i586.rpm
Mandrakelinux 10.0
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva liblm_sensors3-devel-2.8.4-2.1.C30mdk.i586.rpm
Corporate 3.0
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva liblm_sensors3-static-devel-2.8.4-2.1.100mdk.i586.rpm
Mandrakelinux 10.0
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva liblm_sensors3-static-devel-2.8.4-2.1.C30mdk.i586.rpm
Corporate 3.0
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva lm_sensors-2.8.4-2.1.100mdk.amd64.rpm
Mandrakelinux 10.0/AMD64
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva lm_sensors-2.8.4-2.1.100mdk.i586.rpm
Mandrakelinux 10.0
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva lm_sensors-2.8.4-2.1.C30mdk.i586.rpm
Corporate 3.0
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva lm_sensors-2.8.4-2.1.C30mdk.x86_64.rpm
Corporate 3.0/X86_64
http://www1.mandrivalinux.com/en/ftp.php3
lm_sensors lm_sensors 2.8.6
Conectiva liblm_sensors3-2.8.6-61068U10_1cl.i386.rpm
Conectiva 10
ftp://atualizacoes.conectiva.com.br/10/RPMS/liblm_sensors3-2.8.6-61068 U10_1cl.i386.rpm
Conectiva lm_sensors-2.8.6-61068U10_1cl.i386.rpm
Conectiva 10
ftp://atualizacoes.conectiva.com.br/10/RPMS/lm_sensors-2.8.6-61068U10_ 1cl.i386.rpm
Conectiva lm_sensors-devel-2.8.6-61068U10_1cl.i386.rpm
Conectiva 10
ftp://atualizacoes.conectiva.com.br/10/RPMS/lm_sensors-devel-2.8.6-610 68U10_1cl.i386.rpm
Conectiva lm_sensors-devel-static-2.8.6-61068U10_1cl.i386.rpm
Conectiva 10
ftp://atualizacoes.conectiva.com.br/10/RPMS/lm_sensors-devel-static-2. 8.6-61068U10_1cl.i386.rpm
Conectiva lm_sensors-doc-2.8.6-61068U10_1cl.i386.rpm
Conectiva 10
ftp://atualizacoes.conectiva.com.br/10/RPMS/lm_sensors-doc-2.8.6-61068 U10_1cl.i386.rpm
Conectiva lm_sensors-sensord-2.8.6-61068U10_1cl.i386.rpm
Conectiva 10
ftp://atualizacoes.conectiva.com.br/10/RPMS/lm_sensors-sensord-2.8.6-6 1068U10_1cl.i386.rpm
Conectiva lm_sensors-tellerstats-2.8.6-61068U10_1cl.i386.rpm
Conectiva 10
ftp://atualizacoes.conectiva.com.br/10/RPMS/lm_sensors-tellerstats-2.8 .6-61068U10_1cl.i386.rpm
lm_sensors lm_sensors 2.8.7
Mandriva liblm_sensors3-2.8.7-7.1.101mdk.i586.rpm
Mandrakelinux 10.1
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva liblm_sensors3-2.9.0-4.1.102mdk.i586.rpm
Mandrakelinux 10.2
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva liblm_sensors3-devel-2.8.7-7.1.101mdk.i586.rpm
Mandrakelinux 10.1
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva liblm_sensors3-devel-2.9.0-4.1.102mdk.i586.rpm
Mandrakelinux 10.2
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva liblm_sensors3-static-devel-2.8.7-7.1.101mdk.i586.rpm
Mandrakelinux 10.1
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva lm_sensors-2.8.7-7.1.101mdk.i586.rpm
Mandrakelinux 10.1
http://www1.mandrivalinux.com/en/ftp.php3
Mandriva lm_sensors-2.8.7-7.1.101mdk.x86_64.rpm
Mandrakelinux 10.1/X86_64
http://www1.mandrivalinux.com/en/ftp.php3
RedHat Fedora lm_sensors-2.8.7-2.FC3.1.i386.rpm
Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
RedHat Fedora lm_sensors-2.8.7-2.FC3.1.x86_64.rpm
Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
RedHat Fedora lm_sensors-debuginfo-2.8.7-2.FC3.1.i386.rpm
Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
RedHat Fedora lm_sensors-debuginfo-2.8.7-2.FC3.1.x86_64.rpm
Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
RedHat Fedora lm_sensors-devel-2.8.7-2.FC3.1.i386.rpm
Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
RedHat Fedora lm_sensors-devel-2.8.7-2.FC3.1.x86_64.rpm
Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
lm_sensors lm_sensors 2.
参考网址
来源: UBUNTU
名称: USN-172-1
链接:http://www.ubuntulinux.org/support/documentation/usn/usn-172-1
来源: BID
名称: 14624
链接:http://www.securityfocus.com/bid/14624
来源: secure.netroedge.com
链接:http://secure.netroedge.com/~lm78/cvs/lm_sensors2/CHANGES
来源: bugs.debian.org
链接:http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=324193
来源: REDHAT
名称: RHSA-2005:825
链接:http://www.redhat.com/support/errata/RHSA-2005-825.html
来源: MANDRIVA
名称: MDKSA-2005:149
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2005:149
来源: VUPEN
名称: ADV-2005-1492
链接:http://www.frsirt.com/english/advisories/2005/1492
来源: DEBIAN
名称: DSA-814
链接:http://www.debian.org/security/2005/dsa-814
来源: SECTRACK
名称: 1015180
链接:http://securitytracker.com/id?1015180
来源: SECUNIA
名称: 17535
链接:http://secunia.com/advisories/17535
来源: SECUNIA
名称: 17499
链接:http://secunia.com/advisories/17499
来源: SECUNIA
名称: 16501
链接:http://secunia.com/advisories/16501
受影响实体
- Lm_sensors Lm_sensors:2.8.2<!--2000-1-1-->
- Lm_sensors Lm_sensors:2.8.3<!--2000-1-1-->
- Lm_sensors Lm_sensors:2.8.8<!--2000-1-1-->
- Lm_sensors Lm_sensors:2.9.0<!--2000-1-1-->
- Lm_sensors Lm_sensors:2.8.4<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...