让您全面了解并上手亿速云产品
常见入门级使用教程
对外 API 开发文档中心
您历史提交的工单
您的每一条意见,我们都严谨处理
您的每一条建议,我们都认真对待
CNNVD-ID编号 | CNNVD-200912-166 | CVE编号 | CVE-2009-4135 |
发布时间 | 2009-12-11 | 更新时间 | 2009-12-14 |
漏洞类型 | 后置链接 | 漏洞来源 | N/A |
危险等级 | 中危 | 威胁类型 | 本地 |
厂商 | gnu |
GNU coreutils中的dist-check.mk中的distcheck规则,本地用户可以借助一个目录树under /tmp中的一个文件的symlink攻击获得特权。
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
MandrakeSoft Linux Mandrake 2010.0 x86_64
Mandriva coreutils-7.5-2.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva coreutils-doc-7.5-2.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Linux Mandrake 2009.1 x86_64
Mandriva coreutils-7.1-2.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva coreutils-doc-7.1-2.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Linux Mandrake 2009.0
Mandriva coreutils-6.12-2.5mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva coreutils-doc-6.12-2.5mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5 x86_64
Mandriva coreutils-6.12-2.5mdvmes5.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva coreutils-doc-6.12-2.5mdvmes5.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0
Mandriva coreutils-5.2.1-8.1.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/
Mandriva coreutils-doc-5.2.1-8.1.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Linux Mandrake 2009.0 x86_64
Mandriva coreutils-6.12-2.5mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva coreutils-doc-6.12-2.5mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Linux Mandrake 2008.0 x86_64
Mandriva coreutils-6.9-5.1mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva coreutils-doc-6.9-5.1mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5
Mandriva coreutils-6.12-2.5mdvmes5.i586.rpm
http://www.mandriva.com/en/download/
Mandriva coreutils-doc-6.12-2.5mdvmes5.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Linux Mandrake 2008.0
Mandriva coreutils-6.9-5.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva coreutils-doc-6.9-5.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Linux Mandrake 2009.1
Mandriva coreutils-7.1-2.1mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/
Mandriva coreutils-doc-7.1-2.1mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Linux Mandrake 2010.0
Mandriva coreutils-7.5-2.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva coreutils-doc-7.5-2.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0 x86_64
Mandriva coreutils-5.2.1-8.1.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva coreutils-doc-5.2.1-8.1.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/
来源: bugzilla.redhat.com
来源: MLIST
名称: [bug-coreutils] 20091209 [PATCH] doc: NEWS: mention the "make distcheck" vulnerability
链接:http://www.mail-archive.com/bug-coreutils@gnu.org/msg18787.html
来源: MLIST
名称: [bug-coreutils] 20091208 Re: build: distcheck: do not leave a $TMPDIR/coreutils directory behind
链接:http://www.mail-archive.com/bug-coreutils@gnu.org/msg18779.html
来源: SECUNIA
名称: 37645
来源: MLIST
名称: [oss-security] 20091208 Re: CVE Request -- coreutils -- unsafe temporary directory location use
来源: FEDORA
名称: FEDORA-2009-13181
链接:https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00972.html
来源: FEDORA
名称: FEDORA-2009-13216
链接:https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00954.html
来源: XF
名称: gnu-core-distcheck-symlink(54673)
来源: VUPEN
名称: ADV-2009-3453
来源: BID
名称: 37256
来源: OSVDB
名称: 60853
来源: MLIST
名称: [oss-security] 20091208 CVE Request -- coreutils -- unsafe temporary directory location use
来源: SECUNIA
名称: 37860