Рекомендация Debian по безопасности

DSA-193-1 kdenetwork -- переполнение буфера

Дата сообщения:
11.11.2002
Затронутые пакеты:
kdenetwork
Уязвим:
Да
Ссылки на базы данных по безопасности:
В базе данных Bugtraq (на SecurityFocus): Идентификатор BugTraq 6157.
В каталоге Mitre CVE: CVE-2002-1247.
Более подробная информация:

iDEFENSE сообщает об уязвимости в пакете klisa, предоставляющем службу информации локальной сети, схожую с Сетевым окружением, уязвимость обнаружена Texonet. Локальный злоумышленник может использовать состояние переполнения буфера в resLISa, ограниченной версии KLISa. Эта уязвимость присутствует в коде для грамматического разбора переменной окружения LOGNAME, чрезмерно большое значение перезаписывает указатель инструкции, что позволяет злоумышленнику перехватывать управление исполняемым файлом.

Эта проблема была исправлена в версии 2.2.2-14.2 в текущем стабильном выпуске (woody) и в версии 2.2.2-14.3 в нестабильном выпуске (sid). Предыдущий стабильный выпуск (potato) не подвержен данной проблеме, так как в нём отсутствует пакет kdenetwork.

Рекомендуется как можно скорее обновить пакет klisa.

Исправлено в:

Debian GNU/Linux 3.0 (woody)

Исходный код:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdenetwork_2.2.2-14.2.dsc
http://security.debian.org/pool/updates/main/k/kdenetwork/kdenetwork_2.2.2-14.2.diff.gz
http://security.debian.org/pool/updates/main/k/kdenetwork/kdenetwork_2.2.2.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_alpha.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_arm.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_i386.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_ia64.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_ia64.deb
HP Precision:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_hppa.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_m68k.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_mips.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_mipsel.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_powerpc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_s390.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/k/kdenetwork/kdict_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kit_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/klisa_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kmail_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knewsticker_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/knode_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/korn_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/kppp_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ksirc_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/ktalkd_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libkdenetwork1_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib-dev_2.2.2-14.2_sparc.deb
http://security.debian.org/pool/updates/main/k/kdenetwork/libmimelib1_2.2.2-14.2_sparc.deb

Контрольные суммы MD5 этих файлов доступны в исходном сообщении.