漏洞信息详情
Rob Brown Net-Server Perl模块日志函数格式化字符串漏洞
漏洞简介
Net::Server 0.87及更早版本中的log函数存在格式化字符串漏洞,在用于Postfix Greylisting Policy Server (Postgrey) 1.18及更早版本以及可能的其他产品上时,远程攻击者可以通过一个在发送给syslog之前未正确处理的格式化字符串限定符来发起拒绝服务攻击(崩溃)。如使用给Postgrey的发送方地址。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接: Rob Brown Net-Server 0.85 Mandriva perl-Net-Server-0.85-3.1.C30mdk.noarch.rpm Corporate 3.0: http://wwwnew.mandriva.com/en/downloads/ Rob Brown Net-Server 0.87 Debian libnet-server-perl_0.87-3sarge1_all.deb Debian GNU/Linux 3.1 alias sarge http://security.debian.org/pool/updates/main/libn/libnet-server-perl/l ibnet-server-perl_0.87-3sarge1_all.deb Postgrey Postgrey 1.16 Postgrey postgrey-1.21.tar.gz http://isg.ee.ethz.ch/tools/postgrey/pub/postgrey-1.21.tar.gz Postgrey Postgrey 1.17 Postgrey postgrey-1.21.tar.gz http://isg.ee.ethz.ch/tools/postgrey/pub/postgrey-1.21.tar.gz Postgrey Postgrey 1.18 Postgrey postgrey-1.21.tar.gz http://isg.ee.ethz.ch/tools/postgrey/pub/postgrey-1.21.tar.gz Postgrey Postgrey 1.21 Debian postgrey_1.21-1sarge1_all.deb Debian GNU/Linux 3.1 alias sarge http://security.debian.org/pool/updates/main/p/postgrey/postgrey_1.21- 1sarge1_all.deb
参考网址
来源: SECUNIA 名称: 14958 链接:http://secunia.com/advisories/14958 来源: MLIST 名称: [postgrey] 20050414 ANNOUNCE: Postgrey 1.21 (SECURITY) 链接:http://lists.ee.ethz.ch/postgrey/msg00647.html 来源: XF 名称: postgrey-logging-dos(20108) 链接:http://xforce.iss.net/xforce/xfdb/20108 来源: OSVDB 名称: 15517 链接:http://www.osvdb.org/15517 来源: FULLDISC 名称: 20050415 Use of function "log" in Perl module Net::Server 链接:http://marc.theaimsgroup.com/?l=full-disclosure&m=111354538331167&w=2 来源: MLIST 名称: [postgrey] 20050414 Re: Problem with crashing postgrey 链接:http://lists.ee.ethz.ch/postgrey/msg00630.html 来源: MLIST 名称: [postgrey] 20050414 Problem with crashing postgrey 链接:http://lists.ee.ethz.ch/postgrey/msg00627.html 来源: BID 名称: 13193 链接:http://www.securityfocus.com/bid/13193 来源: MANDRIVA 名称: MDKSA-2006:131 链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:131 来源: GENTOO 名称: GLSA-200608-18 链接:http://www.gentoo.org/security/en/glsa/glsa-200608-18.xml 来源: DEBIAN 名称: DSA-1122 链接:http://www.debian.org/security/2006/dsa-1122 来源: DEBIAN 名称: DSA-1121 链接:http://www.debian.org/security/2006/dsa-1121 来源: SECUNIA 名称: 21452 链接:http://secunia.com/advisories/21452 来源: SECUNIA 名称: 21164 链接:http://secunia.com/advisories/21164 来源: SECUNIA 名称: 21152 链接:http://secunia.com/advisories/21152 来源: SECUNIA 名称: 21149 链接:http://secunia.com/advisories/21149 来源: MANDRIVA 名称: MDKSA-2006:131 链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:131
受影响实体
- Postgrey Postgrey:1.17<!--2000-1-1-->
- Postgrey Postgrey:1.18<!--2000-1-1-->
- Postgrey Postgrey:1.16<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...