漏洞信息详情
SWORD Diatheke脚本任意命令执行漏洞
漏洞简介
Sword 1.5.7a中的diatheke.pl使得远程攻击者可以通过在URL内的shell元字符来执行任意命令。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
The SWORD Project SWORD 1.5.3
Debian diatheke_1.5.3-3woody2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3w oody2_alpha.deb
Debian diatheke_1.5.3-3woody2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3w oody2_arm.deb
Debian diatheke_1.5.3-3woody2_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3w oody2_hppa.deb
Debian diatheke_1.5.3-3woody2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3w oody2_i386.deb
Debian diatheke_1.5.3-3woody2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3w oody2_ia64.deb
Debian diatheke_1.5.3-3woody2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3w oody2_m68k.deb
Debian diatheke_1.5.3-3woody2_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3w oody2_mips.deb
Debian diatheke_1.5.3-3woody2_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3w oody2_mipsel.deb
Debian diatheke_1.5.3-3woody2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3w oody2_powerpc.deb
Debian diatheke_1.5.3-3woody2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3w oody2_s390.deb
Debian diatheke_1.5.3-3woody2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/diatheke_1.5.3-3w oody2_sparc.deb
Debian libsword-dev_1.5.3-3woody2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5. 3-3woody2_alpha.deb
Debian libsword-dev_1.5.3-3woody2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5. 3-3woody2_arm.deb
Debian libsword-dev_1.5.3-3woody2_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5. 3-3woody2_hppa.deb
Debian libsword-dev_1.5.3-3woody2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5. 3-3woody2_i386.deb
Debian libsword-dev_1.5.3-3woody2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5. 3-3woody2_ia64.deb
Debian libsword-dev_1.5.3-3woody2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5. 3-3woody2_m68k.deb
Debian libsword-dev_1.5.3-3woody2_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5. 3-3woody2_mips.deb
Debian libsword-dev_1.5.3-3woody2_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5. 3-3woody2_mipsel.deb
Debian libsword-dev_1.5.3-3woody2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5. 3-3woody2_powerpc.deb
Debian libsword-dev_1.5.3-3woody2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5. 3-3woody2_s390.deb
Debian libsword-dev_1.5.3-3woody2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/libsword-dev_1.5. 3-3woody2_sparc.deb
Debian libsword-runtime_1.5.3-3woody2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/libsword-runtime_ 1.5.3-3woody2_alpha.deb
Debian libsword-runtime_1.5.3-3woody2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/sword/libsword-runtime_ 1.5.3-3woody2_arm.deb
Debian libsword-runtime_1
参考网址
来源: DEBIAN
名称: DSA-650
链接:http://www.debian.org/security/2005/dsa-650
来源: XF
名称: sword-diatheke-command-execution(18997)
链接:http://xforce.iss.net/xforce/xfdb/18997
来源: SECTRACK
名称: 1012955
链接:http://securitytracker.com/id?1012955
来源: SECUNIA
名称: 13897
链接:http://secunia.com/advisories/13897
来源: BID
名称: 12320
链接:http://www.securityfocus.com/bid/12320
来源: SECUNIA
名称: 13941
链接:http://secunia.com/advisories/13941
受影响实体
- Crosswire_bible_society Sword:1.5.7a<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...