Debians sikkerhedsbulletin
DSA-144-1 wwwoffle -- uhensigtsmæssig håndtering af inddata
- Rapporteret den:
- 6. aug 2002
- Berørte pakker:
- wwwoffle
- Sårbar:
- Ja
- Referencer i sikkerhedsdatabaser:
- I Bugtraq-databasen (hos SecurityFocus): BugTraq-id 5260.
I Mitres CVE-ordbog: CVE-2002-0818. - Yderligere oplysninger:
-
Der er opdaget er problem i wwwoffle. Webproxy'en håndterede ikke inddata med negative "Content-Length"-indstillinger på en hensigtsmæssigmåde, hvilket fik den behandlende underproces til at gå ned.
Desuden bliver tomme adgangskoder behandlet som forkerte i woody-versionen, når man prøver at blive autentificeret. I woody-versionen erstattede vi også CanonicaliseHost() med den seneste rutine fra 2.7d, som stilles til rådighed af opstrømsudvikleren. Dette forhindrer dårlige IP-adresser i IPv6-format i URL'er i at give problemer (hukommelsesoverskrivelse, potentielle udnyttelser).
Dette problem er rettet i version 2.5c-10.4 i den gamle stabile distribution (potato), i version 2.7a-1.2 i den aktuelle stabile distribution (woody) og i version 2.7d-1 i den ustabile distribution (sid).
Vi anbefaler at du opgraderer dine wwwoffle-pakker.
- Rettet i:
-
Debian GNU/Linux 2.2 (potato)
- Kildekode:
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.5c-10.4.dsc
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.5c-10.4.diff.gz
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.5c.orig.tar.gz
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.5c-10.4.diff.gz
- Alpha:
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.5c-10.4_alpha.deb
- ARM:
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.5c-10.4_arm.deb
- Intel IA-32:
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.5c-10.4_i386.deb
- Motorola 680x0:
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.5c-10.4_m68k.deb
- PowerPC:
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.5c-10.4_powerpc.deb
- Sun Sparc:
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.5c-10.4_sparc.deb
Debian GNU/Linux 3.0 (woody)
- Kildekode:
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.7a-1.2.dsc
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.7a-1.2.diff.gz
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.7a.orig.tar.gz
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.7a-1.2.diff.gz
- Alpha:
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.7a-1.2_alpha.deb
- ARM:
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.7a-1.2_arm.deb
- Intel IA-32:
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.7a-1.2_i386.deb
- Intel IA-64:
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.7a-1.2_ia64.deb
- HP Precision:
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.7a-1.2_hppa.deb
- Motorola 680x0:
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.7a-1.2_m68k.deb
- Big endian MIPS:
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.7a-1.2_mips.deb
- Little endian MIPS:
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.7a-1.2_mipsel.deb
- PowerPC:
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.7a-1.2_powerpc.deb
- IBM S/390:
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.7a-1.2_s390.deb
- Sun Sparc:
- http://security.debian.org/pool/updates/main/w/wwwoffle/wwwoffle_2.7a-1.2_sparc.deb
MD5-kontrolsummer for de listede filer findes i den originale sikkerhedsbulletin.
