Debians sikkerhedsbulletin
DSA-513-1 log2mail -- formatstreng
- Rapporteret den:
- 3. jun 2004
- Berørte pakker:
- log2mail
- Sårbar:
- Ja
- Referencer i sikkerhedsdatabaser:
- I Bugtraq-databasen (hos SecurityFocus): BugTraq-id 10460.
I Mitres CVE-ordbog: CVE-2004-0450. - Yderligere oplysninger:
-
jaguar@felinemenace.org har opdaget en formatstrengssårbarhed i log2mail, hvorved en bruger der har mulighed for at logge en særligt fremstillet meddelelse til en logfil overvåget af log2mail (eksempelvis via syslog), kunne forårsage at vilkårlig kode blev udført med log2mail-processens rettigheder. Som standard kører denne proces som brugeren "log2mail", som er medlem af gruppen "adm" (der har adgang til at læse systemlogfiler).
CAN-2004-0450: log2mail-formatstrengssårbarhed via syslog(3) i printlog()
I den nuværende stabile distribution (woody), er dette problem rettet i version 0.2.5.2.
I den ustabile distribution (sid), vil dette problem snart blive rettet.
Vi anbefaler at du opdaterer din log2mail-pakke.
- Rettet i:
-
Debian GNU/Linux 3.0 (woody)
- Kildekode:
- http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5.2.dsc
- http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5.2.tar.gz
- http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5.2.tar.gz
- Alpha:
- http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5.2_alpha.deb
- ARM:
- http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5.2_arm.deb
- Intel IA-32:
- http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5.2_i386.deb
- Intel IA-64:
- http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5.2_ia64.deb
- HPPA:
- http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5.2_hppa.deb
- Motorola 680x0:
- http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5.2_m68k.deb
- Big endian MIPS:
- http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5.2_mips.deb
- Little endian MIPS:
- http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5.2_mipsel.deb
- PowerPC:
- http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5.2_powerpc.deb
- IBM S/390:
- http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5.2_s390.deb
- Sun Sparc:
- http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5.2_sparc.deb
MD5-kontrolsummer for de listede filer findes i den originale sikkerhedsbulletin.
