首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>漏洞资料>文章内容
Linux Kernel chown()系统调用组属性更改漏洞
来源:vfocus.net 作者:vfocus 发布时间:2004-07-09  

Linux Kernel chown()系统调用组属性更改漏洞


受影响系统:
Linux kernel 2.6.6
Linux kernel 2.6.5
- SuSE Linux 9.1
描述:
--------------------------------------------------------------------------------
BUGTRAQ ID: 10662
CVE(CAN) ID: CAN-2004-0497

Linux是一款开放源代码操作系统。

Linux Kernel存在一个缺陷,本地或远程攻击者可以利用这个漏洞不正确更改任意文件的组属主。

在审核Linux内核过程中,SUSE发现一个缺陷允许用户未授权更改文件组ID,在Red Hat Enterprise
Linux包含2.4版内核,只有通过Kernel nfs服务器上才能触发此问题,在系统上的用户可以从有此漏洞的机器上挂接远程文件系统,并能未授权更改导出文件的组ID。

<*来源:Michael Schroeder
Ruediger Oertel

链接:http://rhn.redhat.com/errata/RHSA-2004-360.html
http://www.securityfocus.com/advisories/6911
*>

建议:
--------------------------------------------------------------------------------
厂商补丁:

RedHat
------
RedHat已经为此发布了一个安全公告(RHSA-2004:360-05)以及相应补丁:
RHSA-2004:360-05:Updated kernel packages fix security vulnerabilities
链接:http://rhn.redhat.com/errata/RHSA-2004-360.html

补丁下载:

Linux kernel 2.6.6:

RedHat Upgrade kernel-2.6.6-1.435.2.3.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
RedHat Fedora Core 2

RedHat Upgrade kernel-smp-2.6.6-1.435.2.3.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
RedHat Fedora Core 2

RedHat Upgrade kernel-debuginfo-2.6.6-1.435.2.3.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
RedHat Fedora Core 2

RedHat Upgrade kernel-sourcecode-2.6.6-1.435.2.3.noarch.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
RedHat Fedora Core 2

RedHat Upgrade kernel-doc-2.6.6-1.435.2.3.noarch.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
RedHat Fedora Core 2

RedHat Upgrade kernel-2.6.6-1.435.2.3.i586.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
RedHat Fedora Core 2

RedHat Upgrade kernel-smp-2.6.6-1.435.2.3.i586.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
RedHat Fedora Core 2

RedHat Upgrade kernel-debuginfo-2.6.6-1.435.2.3.i586.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
RedHat Fedora Core 2

RedHat Upgrade kernel-2.6.6-1.435.2.3.i686.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
RedHat Fedora Core 2

RedHat Upgrade kernel-smp-2.6.6-1.435.2.3.i686.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
RedHat Fedora Core 2

RedHat Upgrade kernel-debuginfo-2.6.6-1.435.2.3.i686.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
RedHat Fedora Core 2

RedHat Upgrade kernel-sourcecode-2.6.6-1.435.2.3.noarch.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
RedHat Fedora Core 2

RedHat Upgrade kernel-doc-2.6.6-1.435.2.3.noarch.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
RedHat Fedora Core 2

RedHat Fedora Core1:

RedHat Upgrade kernel-2.4.22-1.2197.nptl.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
RedHat Fedora Core 1

RedHat Upgrade kernel-smp-2.4.22-1.2197.nptl.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
RedHat Fedora Core 1

RedHat Upgrade kernel-debuginfo-2.4.22-1.2197.nptl.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
RedHat Fedora Core 1

RedHat Upgrade kernel-BOOT-2.4.22-1.2197.nptl.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
RedHat Fedora Core 1

RedHat Upgrade kernel-debuginfo-2.4.22-1.2197.nptl.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
RedHat Fedora Core 1

RedHat Upgrade kernel-2.4.22-1.2197.nptl.i586.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
RedHat Fedora Core 1

RedHat Upgrade kernel-smp-2.4.22-1.2197.nptl.i586.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
RedHat Fedora Core 1

RedHat Upgrade kernel-debuginfo-2.4.22-1.2197.nptl.i586.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
RedHat Fedora Core 1

RedHat Upgrade kernel-2.4.22-1.2197.nptl.i686.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
RedHat Fedora Core 1

RedHat Upgrade kernel-smp-2.4.22-1.2197.nptl.i686.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
RedHat Fedora Core 1

RedHat Upgrade kernel-2.4.22-1.2197.nptl.athlon.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
RedHat Fedora Core 1

RedHat Upgrade kernel-smp-2.4.22-1.2197.nptl.athlon.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
RedHat Fedora Core 1

RedHat Upgrade kernel-debuginfo-2.4.22-1.2197.nptl.athlon.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
RedHat Fedora Core 1

S.u.S.E.
--------
S.u.S.E.已经为此发布了一个安全公告(SUSE-SA:2004:020)以及相应补丁:
SUSE-SA:2004:020:kernel
链接:http://www.securityfocus.com/advisories/6911

补丁下载:

Linux kernel 2.6.5:

SuSE Upgrade kernel-default-2.6.5-7.95.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-default-2.6.5-7.95.i586.rpm
x86 Platform

SuSE Upgrade kernel-smp-2.6.5-7.95.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-smp-2.6.5-7.95.i586.rpm
x86 Platform

SuSE Upgrade kernel-bigsmp-2.6.5-7.95.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-bigsmp-2.6.5-7.95.i586.rpm
x86 Platform

SuSE Upgrade kernel-bigsmp-2.6.5-7.95.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-bigsmp-2.6.5-7.95.i586.rpm
x86 Platform

SuSE Upgrade kernel-source-2.6.5-7.95.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-source-2.6.5-7.95.i586.rpm
x86 Platform

SuSE Upgrade kernel-default-2.6.5-7.95.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kernel-default-2.6.5-7.95.x86_64.rpm
x86-64 Platform

SuSE Upgrade kernel-smp-2.6.5-7.95.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kernel-smp-2.6.5-7.95.x86_64.rpm
x86-64 Platform

SuSE Upgrade kernel-source-2.6.5-7.95.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kernel-source-2.6.5-7.95.x86_64.rpm
x86-64 Platform



 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·XSOK环境变量本地命令执行漏洞
·N点虚拟主机管理系统 致命漏洞。
·南方数据企业网站管理系统V10.0
·动网(DVBBS)Version 8.2.0 后
·Solaris 10 telnet漏洞及解决
·破解无线路由器密码,常见无线密
·Nginx %00空字节执行php漏洞
·WinWebMail、7I24提权漏洞
·XPCD xpcd-svga本地缓冲区溢出漏
·Struts2多个漏洞简要分析
·ecshop2.72 api.php 文件鸡肋注
·Discuz!后台拿Webshell 0day
  相关文章
·Open WebMail Email头字段HTML代
·PureFTPd Accept_Client远程拒绝
·Oracle Database 10g Installer
·Linux Kernel Broadcom 5820 Cry
·Symantec Brightmail Anti-spam
·Easy Chat Server多个远程拒绝服
·Sun Solaris Volume Manager本地
·Microsoft IE Shell.Application
·PHP-Nuke多个SQL注入及跨站脚本
·MySQL验证绕过缓冲区溢出漏洞
·多个Oralce产品本地权限提升漏洞
·3Com SuperStack Switch Web远程
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved