漏洞信息详情
Albatross未明漏洞
漏洞简介
Albatross Web应用程序工具箱1.33之前版本的context.py中存在未指定漏洞,远程攻击者可以通过与模板文件和\"处理已提交的表单字段\"有关的未明向量执行任意命令。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Albatross Albatross 1.20
Debian python-albatross-common_1.20-2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/albatross/python-albatr oss-common_1.20-2_all.deb
Debian python-albatross-doc_1.20-2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/albatross/python-albatr oss-doc_1.20-2_all.deb
Debian python-albatross_1.20-2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/albatross/python-albatr oss_1.20-2_all.deb
Debian python2.2-albatross_1.20-2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/albatross/python2.2-alb atross_1.20-2_all.deb
Debian python2.3-albatross_1.20-2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/albatross/python2.3-alb atross_1.20-2_all.deb
参考网址
来源: VUPEN
名称: ADV-2006-0196
链接:http://www.frsirt.com/english/advisories/2006/0196
来源: DEBIAN
名称: DSA-942
链接:http://www.debian.org/security/2006/dsa-942
来源: SECUNIA
名称: 18457
链接:http://secunia.com/advisories/18457
来源: BID
名称: 16252
链接:http://www.securityfocus.com/bid/16252
来源: www.object-craft.com.au
链接:http://www.object-craft.com.au/projects/albatross/news.html
来源: MISC
链接:http://security.debian.org/pool/updates/main/a/albatross/albatross_1.20-2.diff.gz
来源: XF
名称: albatross-context-command-execution(24130)
链接:http://xforce.iss.net/xforce/xfdb/24130
来源: OSVDB
名称: 22451
链接:http://www.osvdb.org/22451
来源: SECUNIA
名称: 18496
链接:http://secunia.com/advisories/18496
受影响实体
- Albatross Albatross:1.32<!--2000-1-1-->
- Albatross Albatross:1.30<!--2000-1-1-->
- Albatross Albatross:1.20<!--2000-1-1-->
- Albatross Albatross:1.10<!--2000-1-1-->
- Albatross Albatross:1.01<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...