int(1137)

Vulnerability Bulletins


Bug de formato en ez-ipupdate

Vulnerability classification

Property Value
Confidence level Oficial
Impact Integridad
Dificulty Avanzado
Required attacker level Acceso remoto sin cuenta a un servicio estandar

System information

Property Value
Affected manufacturer GNU/Linux
Affected software ez-ipupdate < 3.0.11

Description

Se ha descubierto un bug de formato en el paquete ez-ipupdate, un cliente de algunos servicios de DNS dinámico.La vulnerabilidad puede ser explotada tanto si ez-ipupdate se ejecuta en modo demonio o no, incluso si se está ejecutando en quiet-mode.

Solution



Actualización de software

Mandrake Linux
Mandrakelinux 10.0:
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/RPMS/ez-ipupdate-3.0.11b8-2.1.100mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/SRPMS/ez-ipupdate-3.0.11b8-2.1.100mdk.src.rpm
Mandrakelinux 10.0/AMD64:
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/RPMS/ez-ipupdate-3.0.11b8-2.1.100mdk.amd64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/SRPMS/ez-ipupdate-3.0.11b8-2.1.100mdk.src.rpm
Mandrakelinux 10.1:
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/RPMS/ez-ipupdate-3.0.11b8-2.1.101mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/SRPMS/ez-ipupdate-3.0.11b8-2.1.101mdk.src.rpm
Mandrakelinux 10.1/X86_64:
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/RPMS/ez-ipupdate-3.0.11b8-2.1.101mdk.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/SRPMS/ez-ipupdate-3.0.11b8-2.1.101mdk.src.rpm
Corporate Server 2.1:
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/2.1/RPMS/ez-ipupdate-3.0.11b8-2.1.C21mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/2.1/SRPMS/ez-ipupdate-3.0.11b8-2.1.C21mdk.src.rpm
Corporate Server 2.1/x86_64:
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/2.1/RPMS/ez-ipupdate-3.0.11b8-2.1.C21mdk.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/2.1/SRPMS/ez-ipupdate-3.0.11b8-2.1.C21mdk.src.rpm
Mandrakelinux 9.2:
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/9.2/RPMS/ez-ipupdate-3.0.11b8-2.1.92mdk.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/9.2/SRPMS/ez-ipupdate-3.0.11b8-2.1.92mdk.src.rpm
Mandrakelinux 9.2/AMD64:
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/9.2/RPMS/ez-ipupdate-3.0.11b8-2.1.92mdk.amd64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/9.2/SRPMS/ez-ipupdate-3.0.11b8-2.1.92mdk.src.rpm
Multi Network Firewall 8.2:
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/mnf8.2/RPMS/ez-ipupdate-3.0.11b8-2.1.M82mdk.i586.rpm

Debian

Debian Linux 3.0
Source:
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate_3.0.11b5-1woody2.dsc
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate_3.0.11b5-1woody2.diff.gz
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate_3.0.11b5.orig.tar.gz
Arquitectura Alpha:
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate_3.0.11b5-1woody2_alpha.deb
Arquitectura ARM:
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate_3.0.11b5-1woody2_arm.deb
Arquitectura Intel IA-32:
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate_3.0.11b5-1woody2_i386.deb
Arquitectura Intel IA-64:
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate_3.0.11b5-1woody2_ia64.deb
Arquitectura HP Precision:
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate_3.0.11b5-1woody2_hppa.deb
Arquitectura Motorola 680x0:
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate_3.0.11b5-1woody2_m68k.deb
Arquitectura Big endian MIPS:
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate_3.0.11b5-1woody2_mips.deb
Arquitectura Little endian MIPS:
http://security.debian.org/pool/updates/main/e/ez-pupdate/ez-ipupdate_3.0.11b5-1woody2_mipsel.deb
Arquitectura PowerPC:
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate_3.0.11b5-1woody2_powerpc.deb
Arquitectura IBM S/390:
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate_3.0.11b5-1woody2_s390.deb
Arquitectura Sun Sparc:
http://security.debian.org/pool/updates/main/e/ez-ipupdate/ez-ipupdate_3.0.11b5-1woody2_sparc.deb

Standar resources

Property Value
CVE CAN-2004-0980
BID

Other resources

Mandrakesoft Security Advisories (MDKSA-2004:129)
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:129

Debian Security Advisory (DSA 592-1)
http://lists.debian.org/debian-security-announce/debian-security-announce-2004/msg00201.html

Version history

Version Comments Date
1.0 Aviso emitido 2004-11-11
1.1 Aviso emitido por Debian Linux (DSA 592-1) 2004-11-12
Ministerio de Defensa
CNI
CCN
CCN-CERT