![]() 发布日期:2003-08-12 受影响系统: 描述: pam-pgsql不正确处理用户提交的用户名,当记录消息时可导致发生格式字符串问题。 攻击者提交恶意格式字符串作为用户名给使用PAM验证的程式(如HTTP、SSH、telnet),用户名在随后的pam-pqsql记录日志的过程中会发生格式串处理问题,导致进程内存中的敏感信息被破坏 ,精心构建提交数据可能以使用PAM验证的进程权限在系统上执行任意指令。 <*来源:Debian Security Advisory 厂商补丁:Debian 补丁下载: Source archives: http://security.debian.org/pool/updates/main/p/pam-pgsql/pam-pgsql_0.5.2-3woody1.dsc Alpha architecture: http://security.debian.org/pool/updates/main/p/pam-pgsql/libpam-pgsql_0.5.2-3woody1_alpha.deb ARM architecture: http://security.debian.org/pool/updates/main/p/pam-pgsql/libpam-pgsql_0.5.2-3woody1_arm.deb Intel IA-32 architecture: http://security.debian.org/pool/updates/main/p/pam-pgsql/libpam-pgsql_0.5.2-3woody1_i386.deb Intel IA-64 architecture: http://security.debian.org/pool/updates/main/p/pam-pgsql/libpam-pgsql_0.5.2-3woody1_ia64.deb HP Precision architecture: http://security.debian.org/pool/updates/main/p/pam-pgsql/libpam-pgsql_0.5.2-3woody1_hppa.deb Motorola 680x0 architecture: http://security.debian.org/pool/updates/main/p/pam-pgsql/libpam-pgsql_0.5.2-3woody1_m68k.deb Big endian MIPS architecture: http://security.debian.org/pool/updates/main/p/pam-pgsql/libpam-pgsql_0.5.2-3woody1_mips.deb Little endian MIPS architecture: http://security.debian.org/pool/updates/main/p/pam-pgsql/libpam-pgsql_0.5.2-3woody1_mipsel.deb PowerPC architecture: http://security.debian.org/pool/updates/main/p/pam-pgsql/libpam-pgsql_0.5.2-3woody1_powerpc.deb IBM S/390 architecture: http://security.debian.org/pool/updates/main/p/pam-pgsql/libpam-pgsql_0.5.2-3woody1_s390.deb Sun Sparc architecture: http://security.debian.org/pool/updates/main/p/pam-pgsql/libpam-pgsql_0.5.2-3woody1_sparc.deb 补丁安装方法: 1. 手工安装补丁包: 首先,使用下面的命令来下载补丁软件: 然后,使用下面的命令来安装补丁: 2. 使用apt-get自动安装补丁包: 首先,使用下面的命令更新内部数据库: |
喜欢本文,那就收藏到: |