Vulnerability Bulletins |
Desbordamiento de búfer en libefix |
|
Vulnerability classification |
|
Property | Value |
Confidence level | Oficial |
Impact | Obtener acceso |
Dificulty | Experto |
Required attacker level | Acceso remoto sin cuenta a un servicio exotico |
System information |
|
Property | Value |
Affected manufacturer | GNU/Linux |
Affected software | libefix |
Description |
|
Se ha descubierto un desbordamiento de búfer en libefix. La vulnerabilidad reside en el manejo de las etiquetas de un archivo de imagen en formato EFIX. La explotación de esta vulnerabilidad podría permitir a un atacante remoto ejecutar código arbitrario mediante el uso de una imagen EFIX especialmente diseñada. El código se ejecutaría con los privilegios del usuario que intente visualizar el archivo malicioso. |
|
Solution |
|
Actualización de software Red Hat Linux Red Hat Desktop (v. 4) Red Hat Enterprise Linux AS (v. 4) Red Hat Enterprise Linux ES (v. 4) Red Hat Enterprise Linux WS (v. 4) https://rhn.redhat.com/ Mandrake Linux Mandrakelinux 10.0 x86 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/RPMS/libexif9-0.5.12-3.1.100mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/RPMS/libexif9-devel-0.5.12-3.1.100mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/SRPMS/libexif-0.5.12-3.1.100mdk.src.rpm AMD64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/RPMS/lib64exif9-0.5.12-3.1.100mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/RPMS/lib64exif9-devel-0.5.12-3.1.100mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/SRPMS/libexif-0.5.12-3.1.100mdk.src.rpm Mandrakelinux 10.1 x86 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/RPMS/libexif9-0.5.12-3.1.101mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/RPMS/libexif9-devel-0.5.12-3.1.101mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/SRPMS/libexif-0.5.12-3.1.101mdk.src.rpm X86_64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/RPMS/lib64exif9-0.5.12-3.1.101mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/RPMS/lib64exif9-devel-0.5.12-3.1.101mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/SRPMS/libexif-0.5.12-3.1.101mdk.src.rpm Corporate Server 3.0 x86 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/RPMS/libexif9-0.5.12-3.1.C30mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/RPMS/libexif9-devel-0.5.12-3.1.C30mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/SRPMS/libexif-0.5.12-3.1.C30mdk.src.rpm X86_64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/3.0/RPMS/lib64exif9-0.5.12-3.1.C30mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/3.0/RPMS/lib64exif9-devel-0.5.12-3.1.C30mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/3.0/SRPMS/libexif-0.5.12-3.1.C30mdk.src.rpm Debian Linux Debian Linux 3.0 Source http://security.debian.org/pool/updates/main/libe/libexif/libexif_0.5.0-1woody1.dsc http://security.debian.org/pool/updates/main/libe/libexif/libexif_0.5.0-1woody1.diff.gz http://security.debian.org/pool/updates/main/libe/libexif/libexif_0.5.0.orig.tar.gz Alpha http://security.debian.org/pool/updates/main/libe/libexif/libexif-dev_0.5.0-1woody1_alpha.deb http://security.debian.org/pool/updates/main/libe/libexif/libexif5_0.5.0-1woody1_alpha.deb ARM http://security.debian.org/pool/updates/main/libe/libexif/libexif-dev_0.5.0-1woody1_arm.deb http://security.debian.org/pool/updates/main/libe/libexif/libexif5_0.5.0-1woody1_arm.deb Intel IA-32 http://security.debian.org/pool/updates/main/libe/libexif/libexif-dev_0.5.0-1woody1_i386.deb http://security.debian.org/pool/updates/main/libe/libexif/libexif5_0.5.0-1woody1_i386.deb Intel IA-64 http://security.debian.org/pool/updates/main/libe/libexif/libexif-dev_0.5.0-1woody1_ia64.deb http://security.debian.org/pool/updates/main/libe/libexif/libexif5_0.5.0-1woody1_ia64.deb HP Precision http://security.debian.org/pool/updates/main/libe/libexif/libexif-dev_0.5.0-1woody1_hppa.deb http://security.debian.org/pool/updates/main/libe/libexif/libexif5_0.5.0-1woody1_hppa.deb Motorola 680x0 http://security.debian.org/pool/updates/main/libe/libexif/libexif-dev_0.5.0-1woody1_m68k.deb http://security.debian.org/pool/updates/main/libe/libexif/libexif5_0.5.0-1woody1_m68k.deb Big endian MIPS http://security.debian.org/pool/updates/main/libe/libexif/libexif-dev_0.5.0-1woody1_mips.deb http://security.debian.org/pool/updates/main/libe/libexif/libexif5_0.5.0-1woody1_mips.deb Little endian MIPS http://security.debian.org/pool/updates/main/libe/libexif/libexif-dev_0.5.0-1woody1_mipsel.deb http://security.debian.org/pool/updates/main/libe/libexif/libexif5_0.5.0-1woody1_mipsel.deb PowerPC http://security.debian.org/pool/updates/main/libe/libexif/libexif-dev_0.5.0-1woody1_powerpc.deb http://security.debian.org/pool/updates/main/libe/libexif/libexif5_0.5.0-1woody1_powerpc.deb IBM S/390 http://security.debian.org/pool/updates/main/libe/libexif/libexif-dev_0.5.0-1woody1_s390.deb http://security.debian.org/pool/updates/main/libe/libexif/libexif5_0.5.0-1woody1_s390.deb Sun Sparc http://security.debian.org/pool/updates/main/libe/libexif/libexif-dev_0.5.0-1woody1_sparc.deb http://security.debian.org/pool/updates/main/libe/libexif/libexif5_0.5.0-1woody1_sparc.deb SUSE Linux Actualizar mediante YaST Online Update Sun Solaris 10 / SPARC / patch 121095-01 Solaris 10 / x86 / patch 121096-01 Java Desktop System (JDS) Release 2 / x86 / Solaris 9 / patch 121093-01 Java Desktop System (JDS) Release 2 / Linux / patch-9996 http://sunsolve.sun.com/pub-cgi/show.pl?target=patchpage |
|
Standar resources |
|
Property | Value |
CVE | CAN-2005-0664 |
BID | |
Other resources |
|
Red Hat Security Advisory RHSA-2005:300-08 https://rhn.redhat.com/errata/RHSA-2005-300.html Mandrakesoft Security Advisories MDKSA-2005:064 http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:064 Debian Security Advisory DSA 709-1 http://lists.debian.org/debian-security-announce/debian-security-announce-2005/msg00089.html SUSE Security Summary Report SUSE-SR:2005:011 http://www.novell.com/linux/security/advisories/2005_11_sr.html Sun Alert Notification (102041) http://sunsolve.sun.com/search/document.do?assetkey=1-26-102041-1 |
Version history |
||
Version | Comments | Date |
1.0 | Aviso emitido | 2005-03-22 |
1.1 | Aviso emitido por Mandrake (MDKSA-2005:064) | 2005-04-01 |
1.2 | Aviso emitido por Debian (DSA 709-1). Aviso emitido por SUSE (SUSE-SR:2005:011). | 2005-04-18 |
1.3 | Aviso emitido por Sun (102041) | 2005-11-25 |