Linux Kernel chown()系统调用组属性更改漏洞

admin 2022-07-13 15:56:45 CNNVD漏洞 来源:ZONE.CI 全球网 0 阅读模式

漏洞信息详情

Linux Kernel chown()系统调用组属性更改漏洞

  • CNNVD编号:CNNVD-200412-013
  • 危害等级: 低危
  • CVE编号: CVE-2004-0497
  • 漏洞类型: 访问验证错误
  • 发布时间: 2004-07-05
  • 威胁类型: 本地
  • 更新时间: 2005-10-20
  • 厂        商: trustix
  • 漏洞来源: Michael Schroeder ...

漏洞简介

Linux是一款开放源代码操作系统。 Linux Kernel存在一个缺陷,本地或远程攻击者可以利用这个漏洞不正确更改任意文件的组属主。 在审核Linux内核过程中,SUSE发现一个缺陷允许用户未授权更改文件组ID,在Red Hat Enterprise Linux包含2.4版内核,只有通过Kernel nfs服务器上才能触发此问题,在系统上的用户可以从有此漏洞的机器上挂接远程文件系统,并能未授权更改导出文件的组ID。

漏洞公告

厂商补丁: RedHat ------ RedHat已经为此发布了一个安全公告(RHSA-2004:360-05)以及相应补丁:

RHSA-2004:360-05:Updated kernel packages fix security vulnerabilities

链接: http://rhn.redhat.com/errata/RHSA-2004-360.HTML

补丁下载:

Linux kernel 2.6.6:

RedHat Upgrade kernel-2.6.6-1.435.2.3.x86_64.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

RedHat Fedora Core 2

RedHat Upgrade kernel-smp-2.6.6-1.435.2.3.x86_64.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

RedHat Fedora Core 2

RedHat Upgrade kernel-debuginfo-2.6.6-1.435.2.3.x86_64.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

RedHat Fedora Core 2

RedHat Upgrade kernel-sourcecode-2.6.6-1.435.2.3.noarch.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

RedHat Fedora Core 2

RedHat Upgrade kernel-doc-2.6.6-1.435.2.3.noarch.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

RedHat Fedora Core 2

RedHat Upgrade kernel-2.6.6-1.435.2.3.i586.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

RedHat Fedora Core 2

RedHat Upgrade kernel-smp-2.6.6-1.435.2.3.i586.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

RedHat Fedora Core 2

RedHat Upgrade kernel-debuginfo-2.6.6-1.435.2.3.i586.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

RedHat Fedora Core 2

RedHat Upgrade kernel-2.6.6-1.435.2.3.i686.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

RedHat Fedora Core 2

RedHat Upgrade kernel-smp-2.6.6-1.435.2.3.i686.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

RedHat Fedora Core 2

RedHat Upgrade kernel-debuginfo-2.6.6-1.435.2.3.i686.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

RedHat Fedora Core 2

RedHat Upgrade kernel-sourcecode-2.6.6-1.435.2.3.noarch.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

RedHat Fedora Core 2

RedHat Upgrade kernel-doc-2.6.6-1.435.2.3.noarch.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

RedHat Fedora Core 2

RedHat Fedora Core1:

RedHat Upgrade kernel-2.4.22-1.2197.nptl.x86_64.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/

RedHat Fedora Core 1

RedHat Upgrade kernel-smp-2.4.22-1.2197.nptl.x86_64.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/

RedHat Fedora Core 1

RedHat Upgrade kernel-debuginfo-2.4.22-1.2197.nptl.x86_64.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/

RedHat Fedora Core 1

RedHat Upgrade kernel-BOOT-2.4.22-1.2197.nptl.i386.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/

RedHat Fedora Core 1

RedHat Upgrade kernel-debuginfo-2.4.22-1.2197.nptl.i386.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/

RedHat Fedora Core 1

RedHat Upgrade kernel-2.4.22-1.2197.nptl.i586.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/

RedHat Fedora Core 1

RedHat Upgrade kernel-smp-2.4.22-1.2197.nptl.i586.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/

RedHat Fedora Core 1

RedHat Upgrade kernel-debuginfo-2.4.22-1.2197.nptl.i586.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/

RedHat Fedora Core 1

RedHat Upgrade kernel-2.4.22-1.2197.nptl.i686.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/

RedHat Fedora Core 1

RedHat Upgrade kernel-smp-2.4.22-1.2197.nptl.i686.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/

RedHat Fedora Core 1

RedHat Upgrade kernel-2.4.22-1.2197.nptl.athlon.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/

RedHat Fedora Core 1

RedHat Upgrade kernel-smp-2.4.22-1.2197.nptl.athlon.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/

RedHat Fedora Core 1

RedHat Upgrade kernel-debuginfo-2.4.22-1.2197.nptl.athlon.rpm

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/

RedHat Fedora Core 1 S.u.S.E. -------- S.u.S.E.已经为此发布了一个安全公告(SUSE-SA:2004:020)以及相应补丁:

SUSE-SA:2004:020:kernel

链接: http://www.securityfocus.com/advisories/6911

补丁下载:

Linux kernel 2.6.5:

SuSE Upgrade kernel-default-2.6.5-7.95.i586.rpm

ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-default-2.6.5-7.95.i586.rpm

x86 Platform

SuSE Upgrade kernel-smp-2.6.5-7.95.i586.rpm

ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-smp-2.6.5-7.95.i586.rpm

x86 Platform

SuSE Upgrade kernel-bigsmp-2.6.5-7.95.i586.rpm

ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-bigsmp-2.6.5-7.95.i586.rpm

x86 Platform

SuSE Upgrade kernel-bigsmp-2.6.5-7.95.i586.rpm

ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-bigsmp-2.6.5-7.95.i586.rpm

x86 Platform

SuSE Upgrade kernel-source-2.6.5-7.95.i586.rpm

ftp://ftp.suse.com/pub/suse/

参考网址

来源: XF 名称: linux-fchown-groupid-modify(16599) 链接:http://xforce.iss.net/xforce/xfdb/16599 来源: REDHAT 名称: RHSA-2004:354 链接:http://www.redhat.com/support/errata/RHSA-2004-354.HTML 来源: MANDRAKE 名称: MDKSA-2004:066 链接:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:066 来源: CONECTIVA 名称: CLA-2004:852 链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000852 来源: REDHAT 名称: RHSA-2004:360 链接:http://www.redhat.com/support/errata/RHSA-2004-360.HTML 来源: SUSE 名称: SUSE-SA:2004:020 链接:http://www.novell.com/linux/security/advisories/2004_20_kernel.HTML 来源: OVAL 名称: oval:org.mitre.oval:def:9867 链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9867

受影响实体

  • Trustix Secure_linux:2.1  
  • Trustix Secure_linux:2.0  
  • Trustix Secure_linux:2  

补丁

    暂无

weinxin
特别声明
本站(ZONE.CI)所有文章仅供技术研究,若将其信息做其他用途,由用户承担全部法律及连带责任,本站不承担任何法律及连带责任,请遵守中华人民共和国安全法.
评论:0   参与:  0