Debians sikkerhedsbulletin
DSA-690-1 bsmtpd -- manglende kontrol af inddata
- Rapporteret den:
- 25. feb 2005
- Berørte pakker:
- bsmtpd
- Sårbar:
- Ja
- Referencer i sikkerhedsdatabaser:
- I Mitres CVE-ordbog: CVE-2005-0107.
- Yderligere oplysninger:
-
Bastian Blank har opdaget en sårbarhed i bsmtpd, et program til SMTP-batchudsendelse af mail til brug med sendmail og postfix. Adresser der ikke var kontrolleret, kunne gøre det muligt at udføre vilkårlige kommandoer under hvad der lod til at være en postleverance.
I den stabile distribution (woody) er dette problem rettet i version 2.3pl8b-12woody1.
I den ustabile distribution (sid) er dette problem rettet i version 2.3pl8b-16.
Vi anbefaler at du opgraderer din bsmtpd-pakke.
- Rettet i:
-
Debian GNU/Linux 3.0 (woody)
- Kildekode:
- http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-12woody1.dsc
- http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-12woody1.diff.gz
- http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b.orig.tar.gz
- http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-12woody1.diff.gz
- Alpha:
- http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-12woody1_alpha.deb
- ARM:
- http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-12woody1_arm.deb
- Intel IA-32:
- http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-12woody1_i386.deb
- Intel IA-64:
- http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-12woody1_ia64.deb
- HPPA:
- http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-12woody1_hppa.deb
- Motorola 680x0:
- http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-12woody1_m68k.deb
- Big endian MIPS:
- http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-12woody1_mips.deb
- Little endian MIPS:
- http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-12woody1_mipsel.deb
- PowerPC:
- http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-12woody1_powerpc.deb
- IBM S/390:
- http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-12woody1_s390.deb
- Sun Sparc:
- http://security.debian.org/pool/updates/main/b/bsmtpd/bsmtpd_2.3pl8b-12woody1_sparc.deb
MD5-kontrolsummer for de listede filer findes i den originale sikkerhedsbulletin.