枫情绝舞 2006-5-9 10:54
Perl
受影响系统:
Debian libdbi-perl 1.42-3ubuntu0.1
描述:
--------------------------------------------------------------------------------
CVE(CAN) ID: CAN-2005-0077 DBI::ProxyServer是perl的DBI库包含的模块。 DBI::ProxyServer模块在建立PID文件时不够安全,本地攻击者可以利用这个漏洞通过符号链接以用户进程权限覆盖系统任意文件。 目前没有详细漏洞细节提供。 <*来源:Martin Pitt ([email]martin.pitt@canonical.com[/email])
Javier Fernández-Sanguino Peña 链接:[url]http://marc.theaimsgroup.com/?l=bugtraq&m=110667936707597&w=2[/url]
[url]http://www.debian.org/security/2002/dsa-658[/url]
*> 建议:
--------------------------------------------------------------------------------
厂商补丁: Debian
------
Debian已经为此发布了一个安全公告(DSA-658-1)以及相应补丁:
DSA-658-1:New libdbi-perl packages fix insecure temporary file
链接:[url]http://www.debian.org/security/2002/dsa-658[/url] 补丁下载: Source archives: [url]http://security.debian.org/pool/updates/main/libd/libdbi-perl/libdbi-perl_1.21-2woody2.dsc[/url]
Size/MD5 checksum: 587 778cd2081c6c996e962e5ccd6100b1e8
[url]http://security.debian.org/pool/updates/main/libd/libdbi-perl/libdbi-perl_1.21-2woody2.diff.gz[/url]
Size/MD5 checksum: 12117 b96cca05e51fcab8c6ca55c00644d3fd
[url]http://security.debian.org/pool/updates/main/libd/libdbi-perl/libdbi-perl_1.21.orig.tar.gz[/url]
Size/MD5 checksum: 208384 c781eee2559de5e4a72e28a8120cb1d9 Alpha architecture: [url]http://security.debian.org/pool/updates/main/libd/libdbi-perl/libdbi-perl_1.21-2woody2_alpha.deb[/url]
Size/MD5 checksum: 345058 014d047dbb24fd94d1a1437244644cd8 ARM architecture: [url]http://security.debian.org/pool/updates/main/libd/libdbi-perl/libdbi-perl_1.21-2woody2_arm.deb[/url]
Size/MD5 checksum: 342540 896f3fe01eb1702df395c8f4ea3b6877 Intel IA-32 architecture: [url]http://security.debian.org/pool/updates/main/libd/libdbi-perl/libdbi-perl_1.21-2woody2_i386.deb[/url]
Size/MD5 checksum: 337802 82348c4c37c6636b85b5fa18d5e00f66 Intel IA-64 architecture: [url]http://security.debian.org/pool/updates/main/libd/libdbi-perl/libdbi-perl_1.21-2woody2_ia64.deb[/url]
Size/MD5 checksum: 356854 b800c42bcdbd3fef74ab630f1a066682 HP Precision architecture: [url]http://security.debian.org/pool/updates/main/libd/libdbi-perl/libdbi-perl_1.21-2woody2_hppa.deb[/url]
Size/MD5 checksum: 345808 5cebb7436af6e22050de51ea895a62ed Motorola 680x0 architecture: [url]http://security.debian.org/pool/updates/main/libd/libdbi-perl/libdbi-perl_1.21-2woody2_m68k.deb[/url]
Size/MD5 checksum: 338592 202c8161fcdb618b6fbe236499d560af Big endian MIPS architecture: [url]http://security.debian.org/pool/updates/main/libd/libdbi-perl/libdbi-perl_1.21-2woody2_mips.deb[/url]
Size/MD5 checksum: 338102 3689ef5cf728e7108206cd9140f682bc Little endian MIPS architecture: [url]http://security.debian.org/pool/updates/main/libd/libdbi-pe[/url]
klkovor 2006-11-25 02:12
【新疆论坛_新疆之家_新疆社区】新疆人的网上家园
*** 作者被禁止或删除 内容自动屏蔽 ***