漏洞信息详情

Telnet客户端env_opt_add() 缓冲区溢出漏洞

  • CNNVD编号:CNNVD-200505-503
  • 危害等级: 高危
  • CVE编号: CVE-2005-0468
  • 漏洞类型: 缓冲区溢出
  • 发布时间: 2005-03-29
  • 威胁类型: 远程
  • 更新时间: 2006-09-22
  • 厂        商: ncsa
  • 漏洞来源: Gael DelalleauiDEF...

漏洞简介

TELNET协议是一种实现远程虚拟终端功能的网络协议,目前有多种telnet的服务器及客户端的实现。多个TELNET协议客户端的实现在处理telnet NEW-ENVIRON子协商选项时存在缓冲区溢出漏洞,如果用户使用有漏洞的客户端程序连接访问恶意telnet服务器,可能导致在客户端机器上执行恶意指令。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Heimdal Heimdal 0.6

Heimdal heimdal-0.6.4.tar.gz

ftp://ftp.pdc.kth.se/pub/heimdal/src/heimdal-0.6.4.tar.gz

Heimdal Heimdal 0.6.1

Heimdal heimdal-0.6.4.tar.gz

ftp://ftp.pdc.kth.se/pub/heimdal/src/heimdal-0.6.4.tar.gz

MIT Kerberos 5 1.3.3

Fedora krb5-debuginfo-1.3.6-4.i386.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora krb5-debuginfo-1.3.6-4.x86_64.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora krb5-devel-1.3.6-4.i386.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora krb5-devel-1.3.6-4.x86_64.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora krb5-libs-1.3.6-4.i386.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora krb5-libs-1.3.6-4.x86_64.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora krb5-server-1.3.6-4.i386.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora krb5-server-1.3.6-4.x86_64.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora krb5-workstation-1.3.6-4.i386.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora krb5-workstation-1.3.6-4.x86_64.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

MIT Kerberos 5 1.3.6

Ubuntu krb5-admin-server_1.3.6-1ubuntu0.1_amd64.deb

Ubuntu 5.04 (Hoary Hedgehog)

http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-admin-serv er_1.3.6-1ubuntu0.1_amd64.deb

Ubuntu krb5-admin-server_1.3.6-1ubuntu0.1_powerpc.deb

Ubuntu 5.04 (Hoary Hedgehog)

http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-admin-serv er_1.3.6-1ubuntu0.1_powerpc.deb

Ubuntu krb5-clients_1.3.6-1ubuntu0.1_amd64.deb

Ubuntu 5.04 (Hoary Hedgehog)

http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-clients_1. 3.6-1ubuntu0.1_amd64.deb

Ubuntu krb5-clients_1.3.6-1ubuntu0.1_i386.deb

Ubuntu 5.04 (Hoary Hedgehog)

http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-clients_1. 3.6-1ubuntu0.1_i386.deb

Ubuntu krb5-clients_1.3.6-1ubuntu0.1_powerpc.deb

Ubuntu 5.04 (Hoary Hedgehog)

http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-clients_1. 3.6-1ubuntu0.1_powerpc.deb

Ubuntu krb5-ftpd_1.3.6-1ubuntu0.1_amd64.deb

Ubuntu 5.04 (Hoary Hedgehog)

http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-ftpd_1.3.6 -1ubuntu0.1_amd64.deb

Ubuntu krb5-ftpd_1.3.6-1ubuntu0.1_i386.deb

Ubuntu 5.04 (Hoary Hedgehog)

http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-ftpd_1.3.6 -1ubuntu0.1_i386.deb

Ubuntu krb5-ftpd_1.3.6-1ubuntu0.1_powerpc.deb

Ubuntu 5.04 (Hoary Hedgehog)

http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-ftpd_1.3.6 -1ubuntu0.1_powerpc.deb

Ubuntu krb5-kdc_1.3.6-1ubuntu0.1_amd64.deb

Ubuntu 5.04 (Hoary Hedgehog)

http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-kdc_1.3.6- 1ubuntu0.1_amd64.deb

Ubuntu krb5-kdc_1.3.6-1ubuntu0.1_i386.deb

Ubuntu 5.04 (Hoary Hedgehog)

http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-kdc_1.3.6- 1ubuntu0.1_i386.deb

Ubuntu krb5-kdc_1.3.6-1ubuntu0.1_powerpc.deb

Ubuntu 5.04 (Hoary Hedgehog)

http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-kdc_1.3.6- 1ubuntu0.1_powerpc.deb

Ubuntu krb5-rsh-server_1.3.6-1ubuntu0.1_amd64.deb

Ubuntu 5.04 (Hoary Hedgehog)

http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-rsh-server _1.3.6-1ubuntu0.1_amd64.deb

Ubuntu krb5-rsh-server_1.3.6-1ubuntu0.1_i386.deb

Ubuntu 5.04 (Hoary Hedgehog)

http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-rsh-server _1.3.6-1ubuntu0.1_i386.deb

Ubuntu krb5-rsh-server_1.3.6-1ubuntu0.1_powerpc.deb

Ubuntu 5.04 (Hoary Hedgehog)

http://security.ubuntu.com/ubuntu/pool/universe/k/krb5/krb5-rsh-server _1.3.6-1ubuntu0.1_powerpc.deb

Ubuntu krb5-telnetd_1.3.6-1ubuntu0.1_amd

参考网址

来源: US-CERT

名称: VU#341908

链接:http://www.kb.cert.org/vuls/id/341908

来源: REDHAT

名称: RHSA-2005:330

链接:http://www.redhat.com/support/errata/RHSA-2005-330.html

来源: REDHAT

名称: RHSA-2005:327

链接:http://www.redhat.com/support/errata/RHSA-2005-327.html

来源: DEBIAN

名称: DSA-703

链接:http://www.debian.org/security/2005/dsa-703

来源: web.mit.edu

链接:http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-001-telnet.txt

来源: SGI

名称: 20050405-01-P

链接:ftp://patches.sgi.com/support/free/security/advisories/20050405-01-P

来源: UBUNTU

名称: USN-224-1

链接:http://www.ubuntulinux.org/usn/usn-224-1

来源: BID

名称: 12919

链接:http://www.securityfocus.com/bid/12919

来源: IDEFENSE

名称: 20050328 Multiple Telnet Client env_opt_add() Buffer Overflow Vulnerability

链接:http://www.idefense.com/application/poi/display?id=221&type=vulnerabilities

来源: DEBIAN

名称: DSA-731

链接:http://www.debian.de/security/2005/dsa-731

来源: SUNALERT

名称: 57761

链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-57761-1

来源: SUNALERT

名称: 57755

链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-57755-1

来源: SUNALERT

名称: 101671

链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-101671-1

来源: SUNALERT

名称: 101665

链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-101665-1

来源: SECUNIA

名称: 17899

链接:http://secunia.com/advisories/17899

来源: SECUNIA

名称: 14745

链接:http://secunia.com/advisories/14745

来源: CONECTIVA

名称: CLA-2005:962

链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000962

来源: FREEBSD

名称: FreeBSD-SA-05:01.telnet

链接:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:01.telnet.asc

来源: MANDRAKE

名称: MDKSA-2005:061

链接:http://www.mandriva.com/security/advisories?name=MDKSA-2005:061

受影响实体

补丁

    暂无

漏洞信息快速查询

相关漏洞

更多