漏洞信息详情
Business Objects Enterprise/Crystal Reports Server未明拒绝服务攻击漏洞
漏洞简介
Report Application Server (Crystalras.exe)的11.0.0.1370之前版本存在未明漏洞,当用于Business Objects Crystal Reports XI、Crystal Reports Server XI和BusinessObjects Enterprise XI时,远程攻击者可以通过网络流量,可能涉及多个同步TCP连接,来发起拒绝服务攻击(应用程序挂起)。
漏洞公告
目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:
http://ftp1.businessobjects.com/outgoing/EHF/commonXIwin_en.zip
参考网址
来源: BID
名称: 14433
链接:http://www.securityfocus.com/bid/14433
来源: support.businessobjects.com
链接:http://support.businessobjects.com/library/kbase/articles/c2017748.asp
来源: support.businessobjects.com
链接:http://support.businessobjects.com/downloads/critical_updates/security_bulletin_june05.asp
来源: SECUNIA
名称: 16282
链接:http://secunia.com/advisories/16282
来源: XF
名称: business-object-crystal-server-dos(21654)
链接:http://xforce.iss.net/xforce/xfdb/21654
来源: OSVDB
名称: 18473
链接:http://www.osvdb.org/18473
来源: SECTRACK
名称: 1014605
链接:http://securitytracker.com/id?1014605
来源: SECTRACK
名称: 1014604
链接:http://securitytracker.com/id?1014604
受影响实体
- Businessobjects Report_application_server:11.0.0.0<!--2000-1-1-->
- Businessobjects Crystal_reports_xi<!--2000-1-1-->
- Businessobjects Crystal_reports_server_xi<!--2000-1-1-->
- Businessobjects Crystal_enterprise_xi<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...