漏洞信息详情
Dibia jailer 'updatejail' 任意文件重写漏洞
漏洞简介
jailer是一个专为Dibian开发的用户简化jails维护的脚本工具。
jailer中的updatejail允许本地用户借助一个对/tmp/#####.updatejail临时文件的symlink攻击,重写任意文件。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Debian Linux 4.0
Debian jailer_0.4-9+etch1_all.deb
http://security.debian.org/pool/updates/main/j/jailer/jailer_0.4-9+etc h1_all.deb
Debian Linux 4.0 amd64
Debian jailer_0.4-9+etch1_all.deb
http://security.debian.org/pool/updates/main/j/jailer/jailer_0.4-9+etc h1_all.deb
Debian Linux 4.0 mipsel
Debian jailer_0.4-9+etch1_all.deb
http://security.debian.org/pool/updates/main/j/jailer/jailer_0.4-9+etc h1_all.deb
Debian Linux 4.0 ia-32
Debian jailer_0.4-9+etch1_all.deb
http://security.debian.org/pool/updates/main/j/jailer/jailer_0.4-9+etc h1_all.deb
Debian Linux 4.0 arm
Debian jailer_0.4-9+etch1_all.deb
http://security.debian.org/pool/updates/main/j/jailer/jailer_0.4-9+etc h1_all.deb
Debian Linux 4.0 hppa
Debian jailer_0.4-9+etch1_all.deb
http://security.debian.org/pool/updates/main/j/jailer/jailer_0.4-9+etc h1_all.deb
Debian Linux 4.0 sparc
Debian jailer_0.4-9+etch1_all.deb
http://security.debian.org/pool/updates/main/j/jailer/jailer_0.4-9+etc h1_all.deb
Debian Linux 4.0 s/390
Debian jailer_0.4-9+etch1_all.deb
http://security.debian.org/pool/updates/main/j/jailer/jailer_0.4-9+etc h1_all.deb
Debian Linux 4.0 powerpc
Debian jailer_0.4-9+etch1_all.deb
http://security.debian.org/pool/updates/main/j/jailer/jailer_0.4-9+etc h1_all.deb
Debian Linux 4.0 alpha
Debian jailer_0.4-9+etch1_all.deb
http://security.debian.org/pool/updates/main/j/jailer/jailer_0.4-9+etc h1_all.deb
Debian Linux 4.0 ia-64
Debian jailer_0.4-9+etch1_all.deb
http://security.debian.org/pool/updates/main/j/jailer/jailer_0.4-9+etc h1_all.deb
Debian Linux 4.0 mips
Debian jailer_0.4-9+etch1_all.deb
http://security.debian.org/pool/updates/main/j/jailer/jailer_0.4-9+etc h1_all.deb
Debian Linux 4.0 m68k
Debian jailer_0.4-9+etch1_all.deb
http://security.debian.org/pool/updates/main/j/jailer/jailer_0.4-9+etc h1_all.deb
参考网址
来源: BID
名称: 32413
链接:http://www.securityfocus.com/bid/32413
来源: DEBIAN
名称: DSA-1674
链接:http://www.debian.org/security/2008/dsa-1674
来源: SECUNIA
名称: 32959
链接:http://secunia.com/advisories/32959
来源: SECUNIA
名称: 32943
链接:http://secunia.com/advisories/32943
来源: MLIST
名称: [debian-devel] 20080811 Re: Possible mass bug filing: The possibility of attack with the help of symlinks in some Debian packages
链接:http://lists.debian.org/debian-devel/2008/08/msg00285.html
受影响实体
- Javier_fernandez Jailer:0.4<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...