int(3272)

Vulnerability Bulletins


Ejecución de código en unicon-imc2

Vulnerability classification

Property Value
Confidence level Oficial
Impact Obtener acceso
Dificulty Experto
Required attacker level Acceso remoto sin cuenta a un servicio exotico

System information

Property Value
Affected manufacturer GNU/Linux
Affected software unicon-imc2

Description

Se ha descubierto una vulnerabilidad del tipo desbordamiento de búfer en unicon-imc2, una librería para métodos de entrada de caracteres chinos. La vulnerabilidad reside en un uso incorrecto de variables de entorno.

Un atacante remoto podría ejecutar código arbitrario.

Solution



Actualización de software

Debian

Debian Linux 4.0
Source
http://security.debian.org/pool/updates/main/u/unicon/unicon_3.0.4-11etch1.diff.gz
http://security.debian.org/pool/updates/main/u/unicon/unicon_3.0.4.orig.tar.gz
http://security.debian.org/pool/updates/main/u/unicon/unicon_3.0.4-11etch1.dsc
alpha
http://security.debian.org/pool/updates/main/u/unicon/unicon-imc2_3.0.4-11etch1_alpha.deb
amd64
http://security.debian.org/pool/updates/main/u/unicon/unicon-imc2_3.0.4-11etch1_amd64.deb
arm
http://security.debian.org/pool/updates/main/u/unicon/unicon-imc2_3.0.4-11etch1_arm.deb
hppa
http://security.debian.org/pool/updates/main/u/unicon/unicon-imc2_3.0.4-11etch1_hppa.deb
i386
http://security.debian.org/pool/updates/main/u/unicon/unicon-imc2_3.0.4-11etch1_i386.deb
ia64
http://security.debian.org/pool/updates/main/u/unicon/unicon-imc2_3.0.4-11etch1_ia64.deb
mipsel
http://security.debian.org/pool/updates/main/u/unicon/unicon-imc2_3.0.4-11etch1_mipsel.deb
powerpc
http://security.debian.org/pool/updates/main/u/unicon/unicon-imc2_3.0.4-11etch1_powerpc.deb
s390
http://security.debian.org/pool/updates/main/u/unicon/unicon-imc2_3.0.4-11etch1_s390.deb
sparc
http://security.debian.org/pool/updates/main/u/unicon/unicon-imc2_3.0.4-11etch1_sparc.deb

Standar resources

Property Value
CVE CVE-2007-2835
BID

Other resources

Debian Security Advisory (DSA 1328-1)
http://lists.debian.org/debian-security-announce/debian-security-announce-2007/msg00089.html

Version history

Version Comments Date
1.0 Aviso emitido 2007-07-02
Ministerio de Defensa
CNI
CCN
CCN-CERT