漏洞信息详情
SystemImager 'Flamethrower' 任意文件重写漏洞
漏洞简介
flamethrower项目是为了增强SystemImager的多播和操作系统及应用的安装而开发的一个单独封装的多播文件分配系统。
flamethrower 中的flamethrower允许本地用户借助一个对/tmp/multicast.tar.#####临时文件的symlink攻击,重写任意文件。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Debian Linux 4.0
Debian flamethrower_0.1.8-1+etch1_all.deb
http://security.debian.org/pool/updates/main/f/flamethrower/flamethrower_0.1.8-1+etch1_all.deb
Debian Linux 4.0 amd64
Debian flamethrower_0.1.8-1+etch1_all.deb
http://security.debian.org/pool/updates/main/f/flamethrower/flamethrower_0.1.8-1+etch1_all.deb
Debian Linux 4.0 mipsel
Debian flamethrower_0.1.8-1+etch1_all.deb
http://security.debian.org/pool/updates/main/f/flamethrower/flamethrower_0.1.8-1+etch1_all.deb
Debian Linux 4.0 ia-32
Debian flamethrower_0.1.8-1+etch1_all.deb
http://security.debian.org/pool/updates/main/f/flamethrower/flamethrower_0.1.8-1+etch1_all.deb
Debian Linux 4.0 arm
Debian flamethrower_0.1.8-1+etch1_all.deb
http://security.debian.org/pool/updates/main/f/flamethrower/flamethrower_0.1.8-1+etch1_all.deb
Debian Linux 4.0 hppa
Debian flamethrower_0.1.8-1+etch1_all.deb
http://security.debian.org/pool/updates/main/f/flamethrower/flamethrower_0.1.8-1+etch1_all.deb
Debian Linux 4.0 sparc
Debian flamethrower_0.1.8-1+etch1_all.deb
http://security.debian.org/pool/updates/main/f/flamethrower/flamethrower_0.1.8-1+etch1_all.deb
Debian Linux 4.0 s/390
Debian flamethrower_0.1.8-1+etch1_all.deb
http://security.debian.org/pool/updates/main/f/flamethrower/flamethrower_0.1.8-1+etch1_all.deb
Debian Linux 4.0 powerpc
Debian flamethrower_0.1.8-1+etch1_all.deb
http://security.debian.org/pool/updates/main/f/flamethrower/flamethrower_0.1.8-1+etch1_all.deb
Debian Linux 4.0 alpha
Debian flamethrower_0.1.8-1+etch1_all.deb
http://security.debian.org/pool/updates/main/f/flamethrower/flamethrower_0.1.8-1+etch1_all.deb
Debian Linux 4.0 ia-64
Debian flamethrower_0.1.8-1+etch1_all.deb
http://security.debian.org/pool/updates/main/f/flamethrower/flamethrower_0.1.8-1+etch1_all.deb
Debian Linux 4.0 mips
Debian flamethrower_0.1.8-1+etch1_all.deb
http://security.debian.org/pool/updates/main/f/flamethrower/flamethrower_0.1.8-1+etch1_all.deb
Debian Linux 4.0 m68k
Debian flamethrower_0.1.8-1+etch1_all.deb
http://security.debian.org/pool/updates/main/f/flamethrower/flamethrower_0.1.8-1+etch1_all.deb
参考网址
来源: XF
名称: flamethrower-flamethrower-symlink(46717)
链接:http://xforce.iss.net/xforce/xfdb/46717
来源: BID
名称: 32386
链接:http://www.securityfocus.com/bid/32386
来源: DEBIAN
名称: DSA-1676
链接:http://www.debian.org/security/2008/dsa-1676
来源: SECUNIA
名称: 32961
链接:http://secunia.com/advisories/32961
来源: SECUNIA
名称: 32891
链接:http://secunia.com/advisories/32891
来源: MLIST
名称: [debian-devel] 20080811 Re: Possible mass bug filing: The possibility of attack with the help of symlinks in some Debian packages
链接:http://lists.debian.org/debian-devel/2008/08/msg00285.html
来源: MISC
链接:http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506350
受影响实体
- Dann_frazier Flamethrower:0.1.8<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...