漏洞信息详情
Ettercap远程格式化字符串漏洞
- CNNVD编号:CNNVD-200505-1234
- 危害等级: 高危
- CVE编号: CVE-2005-1796
- 漏洞类型: 格式化字符串
- 发布时间: 2005-05-31
- 威胁类型: 远程
- 更新时间: 2005-10-20
- 厂 商: ettercap
- 漏洞来源: The vendor reporte...
漏洞简介
Ettercap的0.7.3之前版本的Ncurses interface (ec_curses.c)中的curses_msg函数存在格式化字符串漏洞,远程攻击者可以执行任意代码。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Ettercap Ettercap 0.6 .b
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
Ettercap Ettercap 0.6 .a
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
Ettercap Ettercap 0.6.3 .1
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
Ettercap Ettercap 0.6.4
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
Ettercap Ettercap 0.6.5
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
Ettercap Ettercap 0.6.6 .6
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
Ettercap Ettercap 0.6.7
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
Ettercap Ettercap 0.6.9
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
Ettercap Ettercap-NG 0.7 .0
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
Ettercap Ettercap-NG 0.7.1
Debian ettercap-common_0.7.1-1sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/ettercap/ettercap-commo n_0.7.1-1sarge1_amd64.deb
Debian ettercap-gtk_0.7.1-1sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/ettercap/ettercap-gtk_0 .7.1-1sarge1_amd64.deb
Debian ettercap_0.7.1-1sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/ettercap/ettercap_0.7.1 -1sarge1_amd64.deb
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
Ettercap Ettercap-NG 0.7.2
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
参考网址
来源: SECUNIA
名称: 15535
链接:http://secunia.com/advisories/15535
来源: ettercap.sourceforge.net
链接:http://ettercap.sourceforge.net/history.php
来源: BID
名称: 13820
链接:http://www.securityfocus.com/bid/13820
来源: VUPEN
名称: ADV-2005-0670
链接:http://www.frsirt.com/english/advisories/2005/0670
来源: SECTRACK
名称: 1014084
链接:http://securitytracker.com/id?1014084
来源: GENTOO
名称: GLSA-200506-07
链接:http://www.gentoo.org/security/en/glsa/glsa-200506-07.xml
来源: DEBIAN
名称: DSA-749
链接:http://www.debian.org/security/2005/dsa-749
来源: SECUNIA
名称: 16000
链接:http://secunia.com/advisories/16000
来源: SECUNIA
名称: 15664
链接:http://secunia.com/advisories/15664
受影响实体
- Ettercap Ettercap:0.7.2
补丁
暂无
评论