漏洞信息详情
Gentoo logrotate logrotate.c writeState函数拒绝服务漏洞
漏洞简介
logrotate 3.7.9及之前版本的logrotate.c中的writeState函数中存在资源管理错误漏洞。上下文攻击者可以借助日志文件名称中的(1)“\n”(换行)或者(2)“\”(反斜杠),导致拒绝服务(循环中断)。该漏洞已经通过在主机名称或者虚拟机名称基础上自动创建的文件名称得到证明。
漏洞公告
目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:
https://bugzilla.redhat.com/show_bug.cgi?id=680797
参考网址
来源: bugzilla.redhat.com
链接:https://bugzilla.redhat.com/show_bug.cgi?id=680797
来源: VUPEN
名称: ADV-2011-0791
链接:http://www.vupen.com/english/advisories/2011/0791
来源: MLIST
名称: [oss-security] 20110323 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/23/11
来源: MLIST
名称: [oss-security] 20110314 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/14/26
来源: MLIST
名称: [oss-security] 20110311 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/11/5
来源: MLIST
名称: [oss-security] 20110311 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/11/3
来源: MLIST
名称: [oss-security] 20110311 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/10/7
来源: MLIST
名称: [oss-security] 20110311 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/10/6
来源: MLIST
名称: [oss-security] 20110310 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/10/3
来源: MLIST
名称: [oss-security] 20110310 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/10/2
来源: MLIST
名称: [oss-security] 20110308 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/08/5
来源: MLIST
名称: [oss-security] 20110307 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/07/6
来源: MLIST
名称: [oss-security] 20110307 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/07/5
来源: MLIST
名称: [oss-security] 20110307 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/07/11
来源: MLIST
名称: [oss-security] 20110306 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/06/6
来源: MLIST
名称: [oss-security] 20110306 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/06/5
来源: MLIST
名称: [oss-security] 20110306 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/06/4
来源: MLIST
名称: [oss-security] 20110306 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/06/3
来源: MLIST
名称: [oss-security] 20110306 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/05/8
来源: MLIST
名称: [oss-security] 20110305 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/05/6
来源: MLIST
名称: [oss-security] 20110305 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/05/4
来源: MLIST
名称: [oss-security] 20110305 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/04/33
来源: MLIST
名称: [oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/04/32
来源: MLIST
名称: [oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/04/31
来源: MLIST
名称: [oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/04/30
来源: MLIST
名称: [oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/04/29
来源: MLIST
名称: [oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/04/28
来源: MLIST
名称: [oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/04/27
来源: MLIST
名称: [oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
链接:http://openwall.com/lists/oss-security/2011/03/04/26
来源: MLIST
名称: [oss-security] 20110304 Re: CVE Request -- logrotate -- nine issues
来源:NSFOCUS 名称:16657 链接:http://www.nsfocus.net/vulndb/16657
受影响实体
- Gentoo Logrotate:3.7.9<!--2000-1-1-->
- Gentoo Logrotate:3.3:R2<!--2000-1-1-->
- Gentoo Logrotate:3.5.9<!--2000-1-1-->
- Gentoo Logrotate:3.7.7<!--2000-1-1-->
- Gentoo Logrotate:3.7.2<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...