漏洞信息详情
GD图形库多个未指定的远程缓冲区溢出漏洞
漏洞简介
libGD(又名GD Graphics Library或libgd2)是美国软件开发者Thomas Boutell所研发的一个开源的用于动态创建图像的库,它支持创建图表、图形和缩略图等。 gd图形库(libgd) 2.0.21及更早版本中的多个缓冲区溢出,可让远程攻击者通过形态异常的图像文件执行任意代码(这些图像文件会因错误调用gdMalloc函数而触发溢出),它是一组与CVE-2004-0990不同的漏洞。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接: wvWare libwmf 0.2.8 Mandriva lib64wmf0.2_7-0.2.8-6.1.C30mdk.x86_64.rpm Corporate 3.0: http://www.mandriva.com/en/download Mandriva lib64wmf0.2_7-devel-0.2.8-6.1.C30mdk.x86_64.rpm Corporate 3.0: http://www.mandriva.com/en/download Mandriva libwmf-0.2.8-6.1.C30mdk.i586.rpm Corporate 3.0: http://www.mandriva.com/en/download Mandriva libwmf-0.2.8-6.1.C30mdk.src.rpm Corporate 3.0: http://www.mandriva.com/en/download Mandriva libwmf-0.2.8-6.1.C30mdk.x86_64.rpm Corporate 3.0: http://www.mandriva.com/en/download Mandriva libwmf0.2_7-0.2.8-6.1.C30mdk.i586.rpm Corporate 3.0: http://www.mandriva.com/en/download Mandriva libwmf0.2_7-devel-0.2.8-6.1.C30mdk.i586.rpm Corporate 3.0: http://www.mandriva.com/en/download GD Graphics Library gdlib 1.8.4 Debian libgd-dev_1.8.4-17.woody4_alpha.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_alpha.deb Debian libgd-dev_1.8.4-17.woody4_arm.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_arm.deb Debian libgd-dev_1.8.4-17.woody4_hppa.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_hppa.deb Debian libgd-dev_1.8.4-17.woody4_i386.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_i386.deb Debian libgd-dev_1.8.4-17.woody4_ia64.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_ia64.deb Debian libgd-dev_1.8.4-17.woody4_m68k.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_m68k.deb Debian libgd-dev_1.8.4-17.woody4_mips.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_mips.deb Debian libgd-dev_1.8.4-17.woody4_mipsel.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_mipsel.deb Debian libgd-dev_1.8.4-17.woody4_powerpc.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_powerpc.deb Debian libgd-dev_1.8.4-17.woody4_s390.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_s390.deb Debian libgd-dev_1.8.4-17.woody4_sparc.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-dev_1.8. 4-17.woody4_sparc.deb Debian libgd-noxpm-dev_1.8.4-17.woody4_alpha.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_alpha.deb Debian libgd-noxpm-dev_1.8.4-17.woody4_arm.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_arm.deb Debian libgd-noxpm-dev_1.8.4-17.woody4_hppa.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_hppa.deb Debian libgd-noxpm-dev_1.8.4-17.woody4_i386.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_i386.deb Debian libgd-noxpm-dev_1.8.4-17.woody4_ia64.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_ia64.deb Debian libgd-noxpm-dev_1.8.4-17.woody4_m68k.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_m68k.deb Debian libgd-noxpm-dev_1.8.4-17.woody4_mips.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_mips.deb Debian libgd-noxpm-dev_1.8.4-17.woody4_mipsel.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_mipsel.deb Debian libgd-noxpm-dev_1.8.4-17.woody4_powerpc.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_powerpc.deb Debian libgd-noxpm-dev_1.8.4-17.woody4_s390.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_s390.deb Debian libgd-noxpm-dev_1.8.4-17.woody4_sparc.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd-noxpm-de v_1.8.4-17.woody4_sparc.deb Debian libgd1-noxpm_1.8.4-17.woody4_arm.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd1-noxpm_1 .8.4-17.woody4_arm.deb Debian libgd1-noxpm_1.8.4-17.woody4_hppa.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd1-noxpm_1 .8.4-17.woody4_hppa.deb Debian libgd1-noxpm_1.8.4-17.woody4_i386.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd1-noxpm_1 .8.4-17.woody4_i386.deb Debian libgd1-noxpm_1.8.4-17.woody4_ia64.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd1-noxpm_1 .8.4-17.woody4_ia64.deb Debian libgd1-noxpm_1.8.4-17.woody4_m68k.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd1-noxpm_1 .8.4-17.woody4_m68k.deb Debian libgd1-noxpm_1.8.4-17.woody4_mips.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd1-noxpm_1 .8.4-17.woody4_mips.deb Debian libgd1-noxpm_1.8.4-17.woody4_mipsel.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd1-noxpm_1 .8.4-17.woody4_mipsel.deb Debian libgd1-noxpm_1.8.4-17.woody4_powerpc.deb Debian GNU/Linux 3.0 alias woody http://security.debian.org/pool/updates/main/libg/libgd/libgd1-noxpm_1 .8.4-17.woody4_powerpc.deb
参考网址
来源: TRUSTIX 名称: 2004-0058 链接:http://www.trustix.org/errata/2004/0058 来源: BID 名称: 11663 链接:http://www.securityfocus.com/bid/11663 来源: SECUNIA 名称: 13179 链接:http://secunia.com/advisories/13179/ 来源: UBUNTU 名称: USN-25-1 链接:http://seclists.org/lists/bugtraq/2004/Nov/0203.html 来源: XF 名称: gd-graphics-gdmalloc-bo(18048) 链接:http://xforce.iss.net/xforce/xfdb/18048 来源: UBUNTU 名称: USN-33-1 链接:http://www.ubuntulinux.org/support/documentation/usn/usn-33-1 来源: REDHAT 名称: RHSA-2006:0194 链接:http://www.redhat.com/support/errata/RHSA-2006-0194.html 来源: REDHAT 名称: RHSA-2004:638 链接:http://www.redhat.com/support/errata/RHSA-2004-638.html 来源: MANDRIVA 名称: MDKSA-2006:122 链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:122 来源: MANDRIVA 名称: MDKSA-2006:114 链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:114 来源: MANDRIVA 名称: MDKSA-2006:113 链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:113 来源: DEBIAN 名称: DSA-601 链接:http://www.debian.org/security/2004/dsa-601 来源: CIAC 名称: P-071 链接:http://www.ciac.org/ciac/bulletins/p-071.shtml 来源: SECUNIA 名称: 21050 链接:http://secunia.com/advisories/21050 来源: SECUNIA 名称: 20824 链接:http://secunia.com/advisories/20824 来源: SECUNIA 名称: 18686 链接:http://secunia.com/advisories/18686 来源: MANDRIVA 名称: MDKSA-2006:122 链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:122 来源: MANDRIVA 名称: MDKSA-2006:114 链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:114 来源: MANDRIVA 名称: MDKSA-2006:113 链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:113 来源: US Government Resource: oval:org.mitre.oval:def:1195 名称: oval:org.mitre.oval:def:1195 链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1195
受影响实体
- Trustix Secure_linux:2.2<!--2000-1-1-->
- Trustix Secure_linux:2.1<!--2000-1-1-->
- Trustix Secure_linux:2.0<!--2000-1-1-->
- Trustix Secure_linux:1.5<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...