Debians sikkerhedsbulletin
DSA-295-1 pptpd -- bufferoverløb
- Rapporteret den:
- 30. apr 2003
- Berørte pakker:
- pptpd
- Sårbar:
- Ja
- Referencer i sikkerhedsdatabaser:
- I Bugtraq-databasen (hos SecurityFocus): BugTraq-id 7316.
I Mitres CVE-ordbog: CVE-2003-0213. - Yderligere oplysninger:
-
Timo Sirainen har opdaget en sårbarhed i pptpd, en "Point to Point Tunneling Server", som implementerer PPTP-over-IPSEC og normalt anvendes til at oprette virtuelle private netværk (VPN). Ved angivelse af en lille pakkelængde, kunne en angriber få en buffer til at løbe over og udføre kode under den brugerid, som kører pptpd, formentlig root. En udnyttelse af dette problem er allerede i omløb.
I den stabile distribution (woody) er dette problem rettet i version 1.1.2-1.4.
I den gamle stabile distribution (potato) er dette problem rettet i version 1.0.0-4.2.
I den ustabile distribution (sid) er dette problem rettet i version 1.1.4-0.b3.2.
Vi anbefaler at du omgående opgraderer din pptpd-pakke.
- Rettet i:
-
Debian GNU/Linux 2.2 (potato)
- Kildekode:
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.0.0-4.2.dsc
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.0.0-4.2.diff.gz
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.0.0.orig.tar.gz
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.0.0-4.2.diff.gz
- Alpha:
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.0.0-4.2_alpha.deb
- ARM:
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.0.0-4.2_arm.deb
- Intel IA-32:
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.0.0-4.2_i386.deb
- Motorola 680x0:
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.0.0-4.2_m68k.deb
- PowerPC:
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.0.0-4.2_powerpc.deb
- Sun Sparc:
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.0.0-4.2_sparc.deb
Debian GNU/Linux 3.0 (woody)
- Kildekode:
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.1.2-1.4.dsc
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.1.2-1.4.diff.gz
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.1.2.orig.tar.gz
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.1.2-1.4.diff.gz
- Alpha:
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.1.2-1.4_alpha.deb
- ARM:
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.1.2-1.4_arm.deb
- Intel IA-32:
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.1.2-1.4_i386.deb
- Intel IA-64:
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.1.2-1.4_ia64.deb
- HPPA:
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.1.2-1.4_hppa.deb
- Motorola 680x0:
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.1.2-1.4_m68k.deb
- Big endian MIPS:
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.1.2-1.4_mips.deb
- Little endian MIPS:
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.1.2-1.4_mipsel.deb
- PowerPC:
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.1.2-1.4_powerpc.deb
- IBM S/390:
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.1.2-1.4_s390.deb
- Sun Sparc:
- http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.1.2-1.4_sparc.deb
MD5-kontrolsummer for de listede filer findes i den originale sikkerhedsbulletin.