漏洞信息详情
VICE监视内存转储文件格式串漏洞
漏洞简介
VICE 1.6到1.14版本的显示器“内存转储”命令存在格式化字符串漏洞。本地用户借助输出字符串里的格式字符串说明符导致服务拒绝(仿真器崩溃)和可能执行任意代码。
漏洞公告
Spiro Trikaliotis , a developer for the VICE project, supplied the following supported patch: http://downloads.securityfocus.com/vulnerabilities/patches/vice-1.14-mon-vuln.patch VICE version 1.15 has been released and resolves this issue. VICE VICE 1.10
- VICE vice-1.15.tar.gz ftp://ftp.funet.fi/pub/cbm/crossplatform/emulators/VICE/vice-1.15.tar. gz
- VICE vice-1.15.tar.gz ftp://ftp.funet.fi/pub/cbm/crossplatform/emulators/VICE/vice-1.15.tar. gz
- VICE vice-1.15.tar.gz ftp://ftp.funet.fi/pub/cbm/crossplatform/emulators/VICE/vice-1.15.tar. gz
- VICE vice-1.15.tar.gz ftp://ftp.funet.fi/pub/cbm/crossplatform/emulators/VICE/vice-1.15.tar. gz
- VICE vice-1.15.tar.gz ftp://ftp.funet.fi/pub/cbm/crossplatform/emulators/VICE/vice-1.15.tar. gz
- VICE vice-1.15.tar.gz ftp://ftp.funet.fi/pub/cbm/crossplatform/emulators/VICE/vice-1.15.tar. gz
- VICE vice-1.15.tar.gz ftp://ftp.funet.fi/pub/cbm/crossplatform/emulators/VICE/vice-1.15.tar. gz
- VICE vice-1.15.tar.gz ftp://ftp.funet.fi/pub/cbm/crossplatform/emulators/VICE/vice-1.15.tar. gz
- VICE vice-1.15.tar.gz ftp://ftp.funet.fi/pub/cbm/crossplatform/emulators/VICE/vice-1.15.tar. gz
参考网址
来源: BID 名称: 10543 链接:http://www.securityfocus.com/bid/10543 来源: XF 名称: vice-memory-dump-format-string(16404) 链接:http://xforce.iss.net/xforce/xfdb/16404 来源: BUGTRAQ 名称: 20040614 VICE emulator format string vulnerability 链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108723630730487&w=2
受影响实体
- Vice Vice:1.13<!--2000-1-1-->
- Vice Vice:1.14<!--2000-1-1-->
- Vice Vice:1.6<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...