Boletines de Vulnerabilidades |
Desbordamiento de búfer en Lynx |
|
Clasificación de la vulnerabilidad |
|
Propiedad | Valor |
Nivel de Confianza | Oficial |
Impacto | Obtener acceso |
Dificultad | Principiante |
Requerimientos del atacante | Acceso remoto sin cuenta a un servicio exotico |
Información sobre el sistema |
|
Propiedad | Valor |
Fabricant afectat | GNU/Linux |
Software afectado | lynx 2.8.2-2.8.5 |
Descripción |
|
Se ha descubierto una vulnerabilidad de desbordamiento de búfer en las versiones que van desde la 2.8.2 hasta la 2.8.5 de Lynx. La vulnerabilidad reside en un desbordamiento de búfer en la zona de pila en la función HTrjis. La explotación de esta vulnerabilidad podría permitir a un atacante remoto ejecutar código arbitrario mediante un servidor NNTP especialmente diseñado, vía ciertas cabeceras de un artículo que causarían que Lynx añadiera caracteres de escape (ESC) hasta desbordar el búfer. |
|
Solución |
|
Actualización de software Mandriva Mandrakelinux 10.1 X86 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/RPMS/lynx-2.8.5-1.1.101mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/SRPMS/lynx-2.8.5-1.1.101mdk.src.rpm X86_64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/RPMS/lynx-2.8.5-1.1.101mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/SRPMS/lynx-2.8.5-1.1.101mdk.src.rpm Corporate Server 2.1 X86 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/2.1/RPMS/lynx-2.8.5-0.10.2.C21mdk.dev.8.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/2.1/SRPMS/lynx-2.8.5-0.10.2.C21mdk.dev.8.src.rpm X86_64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/2.1/RPMS/lynx-2.8.5-0.10.2.C21mdk.dev.8.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/2.1/SRPMS/lynx-2.8.5-0.10.2.C21mdk.dev.8.src.rpm Corporate Server 3.0 X86 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/RPMS/lynx-2.8.5-1.1.C30mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/SRPMS/lynx-2.8.5-1.1.C30mdk.src.rpm X86_64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/3.0/RPMS/lynx-2.8.5-1.1.C30mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/3.0/SRPMS/lynx-2.8.5-1.1.C30mdk.src.rpm Multi Network Firewall 2.0 X86 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/mnf/2.0/RPMS/lynx-2.8.5-1.1.M20mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/mnf/2.0/SRPMS/lynx-2.8.5-1.1.M20mdk.src.rpm Mandrivalinux LE2005 X86 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.2/RPMS/lynx-2.8.5-1.1.102mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.2/SRPMS/lynx-2.8.5-1.1.102mdk.src.rpm X86_64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.2/RPMS/lynx-2.8.5-1.1.102mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.2/SRPMS/lynx-2.8.5-1.1.102mdk.src.rpm Mandrivalinux 2006 X86 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2006.0/RPMS/lynx-2.8.5-4.1.20060mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2006.0/SRPMS/lynx-2.8.5-4.1.20060mdk.src.rpm X86_64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/2006.0/RPMS/lynx-2.8.5-4.1.20060mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/2006.0/SRPMS/lynx-2.8.5-4.1.20060mdk.src.rpm Red Hat Red Hat Desktop (v. 3) / SRPMS lynx-2.8.5-11.1.src.rpm Red Hat Desktop (v. 3) / IA-32 lynx-2.8.5-11.1.i386.rpm Red Hat Desktop (v. 3) / x86_64 lynx-2.8.5-11.1.x86_64.rpm Red Hat Desktop (v. 4) / SRPMS lynx-2.8.5-18.1.src.rpm Red Hat Desktop (v. 4) / IA-32 lynx-2.8.5-18.1.i386.rpm Red Hat Desktop (v. 4) / x86_64 lynx-2.8.5-18.1.x86_64.rpm Red Hat Enterprise Linux AS (v. 2.1) / SRPMS lynx-2.8.4-18.1.1.src.rpm Red Hat Enterprise Linux AS (v. 2.1) / IA-32 lynx-2.8.4-18.1.1.i386.rpm Red Hat Enterprise Linux AS (v. 2.1) / IA-64 lynx-2.8.4-18.1.1.ia64.rpm Red Hat Enterprise Linux AS (v. 3) / SRPMS lynx-2.8.5-11.1.src.rpm Red Hat Enterprise Linux AS (v. 3) / IA-32 lynx-2.8.5-11.1.i386.rpm Red Hat Enterprise Linux AS (v. 3) / IA-64 lynx-2.8.5-11.1.ia64.rpm Red Hat Enterprise Linux AS (v. 3) / PPC lynx-2.8.5-11.1.ppc.rpm Red Hat Enterprise Linux AS (v. 3) / s390 lynx-2.8.5-11.1.s390.rpm Red Hat Enterprise Linux AS (v. 3) / s390x lynx-2.8.5-11.1.s390x.rpm Red Hat Enterprise Linux AS (v. 3) / x86_64 lynx-2.8.5-11.1.x86_64.rpm Red Hat Enterprise Linux AS (v. 4) / SRPMS lynx-2.8.5-18.1.src.rpm Red Hat Enterprise Linux AS (v. 4) / IA-32 lynx-2.8.5-18.1.i386.rpm Red Hat Enterprise Linux AS (v. 4) / IA-64 lynx-2.8.5-18.1.ia64.rpm Red Hat Enterprise Linux AS (v. 4) / PPC lynx-2.8.5-18.1.ppc.rpm Red Hat Enterprise Linux AS (v. 4) / s390 lynx-2.8.5-18.1.s390.rpm Red Hat Enterprise Linux AS (v. 4) / s390x lynx-2.8.5-18.1.s390x.rpm Red Hat Enterprise Linux AS (v. 4) / x86_64 lynx-2.8.5-18.1.x86_64.rpm Red Hat Enterprise Linux ES (v. 2.1) / SRPMS lynx-2.8.4-18.1.1.src.rpm Red Hat Enterprise Linux ES (v. 2.1) / IA-32 lynx-2.8.4-18.1.1.i386.rpm Red Hat Enterprise Linux ES (v. 3) / SRPMS lynx-2.8.5-11.1.src.rpm Red Hat Enterprise Linux ES (v. 3) / IA-32 lynx-2.8.5-11.1.i386.rpm Red Hat Enterprise Linux ES (v. 3) / IA-64 lynx-2.8.5-11.1.ia64.rpm Red Hat Enterprise Linux ES (v. 3) / x86_64 lynx-2.8.5-11.1.x86_64.rpm Red Hat Enterprise Linux ES (v. 4) / SRPMS lynx-2.8.5-18.1.src.rpm Red Hat Enterprise Linux ES (v. 4) / IA-32 lynx-2.8.5-18.1.i386.rpm Red Hat Enterprise Linux ES (v. 4) / IA-64 lynx-2.8.5-18.1.ia64.rpm Red Hat Enterprise Linux ES (v. 4) / x86_64 lynx-2.8.5-18.1.x86_64.rpm Red Hat Enterprise Linux WS (v. 2.1) / SRPMS lynx-2.8.4-18.1.1.src.rpm Red Hat Enterprise Linux WS (v. 2.1) / IA-32 lynx-2.8.4-18.1.1.i386.rpm Red Hat Enterprise Linux WS (v. 3) / SRPMS lynx-2.8.5-11.1.src.rpm Red Hat Enterprise Linux WS (v. 3) / IA-32 lynx-2.8.5-11.1.i386.rpm Red Hat Enterprise Linux WS (v. 3) / IA-64 lynx-2.8.5-11.1.ia64.rpm Red Hat Enterprise Linux WS (v. 3) / x86_64 lynx-2.8.5-11.1.x86_64.rpm Red Hat Enterprise Linux WS (v. 4) / SRPMS lynx-2.8.5-18.1.src.rpm Red Hat Enterprise Linux WS (v. 4) / IA-32 lynx-2.8.5-18.1.i386.rpm Red Hat Enterprise Linux WS (v. 4) / IA-64 lynx-2.8.5-18.1.ia64.rpm Red Hat Enterprise Linux WS (v. 4) / x86_64 lynx-2.8.5-18.1.x86_64.rpm Red Hat Linux Advanced Workstation 2.1 Itanium / SRPMS lynx-2.8.4-18.1.1.src.rpm Red Hat Linux Advanced Workstation 2.1 Itanium / IA-64 lynx-2.8.4-18.1.1.ia64.rpm SGI Advanced Linux Environment 3 / RPM / Patch 10235 ftp://oss.sgi.com/projects/sgi_propack/download/3/updates/RPMS Advanced Linux Environment 3 / SRPM / Patch 10235 ftp://oss.sgi.com/projects/sgi_propack/download/3/updates/SRPMS Debian Debian Linux 3.0 Source http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.3.dsc http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.3.diff.gz http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b.orig.tar.gz Alpha http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.3_alpha.deb ARM http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.3_arm.deb Intel IA-32 http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.3_i386.deb Intel IA-64 http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.3_ia64.deb HP Precision http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.3_hppa.deb Motorola 680x0 http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.3_m68k.deb Big endian MIPS http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.3_mips.deb Little endian MIPS http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.3_mipsel.deb PowerPC http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.3_powerpc.deb IBM S/390 http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.3_s390.deb Sun Sparc http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.3_sparc.deb Debian Linux 3.1 Source http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge1.dsc http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge1.diff.gz http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5.orig.tar.gz Alpha http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge1_alpha.deb AMD64 http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge1_amd64.deb ARM http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge1_arm.deb Intel IA-32 http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge1_i386.deb Intel IA-64 http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge1_ia64.deb HP Precision http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge1_hppa.deb Motorola 680x0 http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge1_m68k.deb Big endian MIPS http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge1_mips.deb Little endian MIPS http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge1_mipsel.deb PowerPC http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge1_powerpc.deb IBM S/390 http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge1_s390.deb Sun Sparc http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge1_sparc.deb Debian (lynx-ssl) Debian Linux 3.0 Source http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.2.dsc http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.2.diff.gz http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b.orig.tar.gz Alpha http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.2_alpha.deb ARM http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.2_arm.deb Intel IA-32 http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.2_i386.deb Intel IA-64 http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.2_ia64.deb HP Precision http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.2_hppa.deb Motorola 680x0 http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.2_m68k.deb Big endian MIPS http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.2_mips.deb Little endian MIPS http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.2_mipsel.deb PowerPC http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.2_powerpc.deb IBM S/390 http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.2_s390.deb Sun Sparc http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.2_sparc.deb Debian (lynx 2.8.5, 2.8.6) Debian Linux 3.0 Source http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1.dsc http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1.diff.gz http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5.orig.tar.gz Architecture independent http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur-wrapper_2.8.5-2.5woody1_all.deb Alpha http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_alpha.deb ARM http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_arm.deb Intel IA-32 http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_i386.deb Intel IA-64 http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_ia64.deb HP Precision http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_hppa.deb Motorola 680x0 http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_m68k.deb Big endian MIPS http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_mips.deb Little endian MIPS http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_mipsel.deb PowerPC http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_powerpc.deb IBM S/390 http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_s390.deb Sun Sparc http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_sparc.deb Debian Linux 3.1 Source http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1.dsc http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1.diff.gz http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6.orig.tar.gz Architecture independent http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur-wrapper_2.8.6-9sarge1_all.deb Alpha http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_alpha.deb AMD64 http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_amd64.deb ARM http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_arm.deb Intel IA-32 http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_i386.deb Intel IA-64 http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_ia64.deb HP Precision http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_hppa.deb Motorola 680x0 http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_m68k.deb Big endian MIPS http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_mips.deb Little endian MIPS http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_mipsel.deb PowerPC http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_powerpc.deb IBM S/390 http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_s390.deb Sun Sparc http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_sparc.deb Suse Linux Las actualizaciones pueden descargarse mediante YAST o del servidor FTP oficial de Suse Linux SCO UnixWare 7.1.3 UnixWare 7.1.4 ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.47 OpenServer 5.0.7 OpenServer 6.0.0 ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.7.1 |
|
Identificadores estándar |
|
Propiedad | Valor |
CVE | CAN-2005-3120 |
BID | |
Recursos adicionales |
|
Mandriva Security Advisory (MDKSA-2005:186) http://www.mandriva.com/security/advisories?name=MDKSA-2005:186 Red Hat Security Advisory (RHSA-2005:803-4) https://rhn.redhat.com/errata/RHSA-2005-803.html SGI Security Advisory (20051003-01-U) ftp://patches.sgi.com/support/free/security/advisories/20051003-01-U.asc Debian Security Advisory (DSA 874-1) http://lists.debian.org/debian-security-announce/debian-security-announce-2005/msg00270.html Debian Security Advisory (DSA 876-1) http://lists.debian.org/debian-security-announce/debian-security-announce-2005/msg00272.html Debian Security Advisory (DSA 1085-1) http://lists.debian.org/debian-security-announce/debian-security-announce-2006/msg00171.html SUSE Security Advisory (SUSE-SR:2005:025) http://www.novell.com/linux/security/advisories/2005_25_sr.html SCO Security Advisory (SCOSA-2005.47) ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.47/SCOSA-2005.47.txt SCO Security Advisory (SCOSA-2006.7.1) ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.7.1/SCOSA-2006.7.1.txt |
Histórico de versiones |
||
Versión | Comentario | Data |
1.0 | Aviso emitido | 2005-10-24 |
1.1 | Aviso emitido por SGI (20051003-01-U) | 2005-10-26 |
1.2 | Avisos emitidos por Debian (DSA 874-1, DSA 876-1) | 2005-10-28 |
1.3 | Aviso emitido por Suse (SUSE-SR:2005:025) | 2005-11-14 |
1.4 | Aviso emitido por SCO (SCOSA-2005.47) | 2005-11-28 |
2.0 | Exploit público disponible. | 2005-11-29 |
2.1 | Aviso emitido por SCO (SCOSA-2006.7) | 2006-01-12 |
2.2 | Aviso actualizado por SCO (SCOSA-2006.7.1) | 2006-01-16 |
2.3 | Aviso emitido por Debian (DSA 1085-1) | 2006-06-02 |