漏洞信息详情
CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Mac OS X PPPD本地格式串内存泄露漏洞
- CNNVD编号:CNNVD-200403-062
- 危害等级: 低危
- CVE编号: CVE-2004-0165
- 漏洞类型: 输入验证
- 发布时间: 2003-07-18
- 威胁类型: 远程
- 更新时间: 2005-05-13
- 厂 商: CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple
- 漏洞来源: Dave G※ daveg@atst...
漏洞简介
Mac OS X是一款使用在Mac机器上的操作系统,基于BSD系统。 CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Mac OS X包含的ppp守护进程不正确处理非法命令行参数,本地攻击者可以利用这个漏洞读取部分pppd进程内存信息。 ppp守护进程默认在Mac OS X系统上安装,存在一个格式串漏洞。不过此格式串问题不允许利用\\%n进行攻击,不过由于在接收命令行参数时缺少过滤,提交给vslprintf()函数时可触发格式串问题,利用这个问题可获得pppd进程内存中的部分信息,如PAP或者CHAP验证信息。
漏洞公告
厂商补丁: CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple ----- 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:
CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Mac OS X Server 10.2.8:
CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Upgrade SecUpdSrvr2004-02-23Jag.dmg
http://www.info.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/kbnum/n120322
CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Mac OS X 10.2.8:
CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Upgrade SecUpd2004-02-23Jag.dmg
http://www.info.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/kbnum/n120277
CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Mac OS X 10.3.2:
CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Upgrade SecUpd2004-02-23Pan.dmg
http://www.info.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/kbnum/n120323
CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Mac OS X Server 10.3.2:
CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Upgrade SecUpdSrvr2004-02-23Pan.dmg
http://www.info.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/kbnum/n120324
参考网址
来源:US-CERT Vulnerability Note: VU#841742 名称: VU#841742 链接:http://www.kb.cert.org/vuls/id/841742 来源: BID 名称: 9730 链接:http://www.securityfocus.com/bid/9730 来源: ATSTAKE 名称: A022304-1 链接:http://www.atstake.com/research/advisories/2004/a022304-1.txt 来源: XF 名称: macos-pppd-format-string(15297) 链接:http://xforce.iss.net/xforce/xfdb/15297 来源: OSVDB 名称: 6822 链接:http://www.osvdb.org/6822 来源: CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple 名称: CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple-SA-2004-02-23 链接:http://lists.CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple.com/archives/security-announce/2004/Feb/msg00000.HTML
受影响实体
- CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Mac_os_x_server:10.3.2
- CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Mac_os_x_server:10.3.1
- CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Mac_os_x_server:10.3
- CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Mac_os_x_server:10.2.8
- CMS.zone.ci/e/tags/htag.php?tag=Apple target=_blank class=infotextkey>Apple Mac_os_x_server:10.2.7
补丁
暂无
![weinxin](http://zone.ci/zone_ci_images/zone.ci.png)
评论