让您全面了解并上手亿速云产品
常见入门级使用教程
对外 API 开发文档中心
您历史提交的工单
您的每一条意见,我们都严谨处理
您的每一条建议,我们都认真对待
CNNVD-ID编号 | CNNVD-200604-158 | CVE编号 | CVE-2006-1695 |
发布时间 | 2006-04-11 | 更新时间 | 2006-04-11 |
漏洞类型 | 设计错误 | 漏洞来源 | This vulnerability was discovered by Jan Braun |
危险等级 | 低危 | 威胁类型 | 本地 |
厂商 | fbida |
当未定义TMPDIR环境变量时,fbi包2.01-1.4中的fbgs脚本允许本地用户借助于对 /var/tmp/fbps-[PID]中的临时文件的符号链接攻击重写任意文件。
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
fbida fbida 2.01
Debian exiftran_2.01-1.2sarge1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/exiftran_2.01-1.2sa rge1_alpha.deb
Debian exiftran_2.01-1.2sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/exiftran_2.01-1.2sa rge1_amd64.deb
Debian exiftran_2.01-1.2sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/exiftran_2.01-1.2sa rge1_arm.deb
Debian exiftran_2.01-1.2sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/exiftran_2.01-1.2sa rge1_hppa.deb
Debian exiftran_2.01-1.2sarge1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/exiftran_2.01-1.2sa rge1_i386.deb
Debian exiftran_2.01-1.2sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/exiftran_2.01-1.2sa rge1_ia64.deb
Debian exiftran_2.01-1.2sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/exiftran_2.01-1.2sa rge1_m68k.deb
Debian exiftran_2.01-1.2sarge1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/exiftran_2.01-1.2sa rge1_mips.deb
Debian exiftran_2.01-1.2sarge1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/exiftran_2.01-1.2sa rge1_mipsel.deb
Debian exiftran_2.01-1.2sarge1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/exiftran_2.01-1.2sa rge1_powerpc.deb
Debian exiftran_2.01-1.2sarge1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/exiftran_2.01-1.2sa rge1_s390.deb
Debian exiftran_2.01-1.2sarge1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/exiftran_2.01-1.2sa rge1_sparc.deb
Debian fbi_2.01-1.2sarge1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/fbi_2.01-1.2sarge1_ alpha.deb
Debian fbi_2.01-1.2sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/fbi_2.01-1.2sarge1_ amd64.deb
Debian fbi_2.01-1.2sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/fbi_2.01-1.2sarge1_ arm.deb
Debian fbi_2.01-1.2sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/fbi_2.01-1.2sarge1_ hppa.deb
Debian fbi_2.01-1.2sarge1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/fbi_2.01-1.2sarge1_ i386.deb
Debian fbi_2.01-1.2sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/fbi_2.01-1.2sarge1_ ia64.deb
Debian fbi_2.01-1.2sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/fbi_2.01-1.2sarge1_ m68k.deb
Debian fbi_2.01-1.2sarge1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/fbi_2.01-1.2sarge1_ mips.deb
Debian fbi_2.01-1.2sarge1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/fbi_2.01-1.2sarge1_ mipsel.deb
Debian fbi_2.01-1.2sarge1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/fbi_2.01-1.2sarge1_ powerpc.deb
Debian fbi_2.01-1.2sarge1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/fbi_2.01-1.2sarge1_ s390.deb
Debian fbi_2.01-1.2sarge1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/f/fbi/fbi_2.01-1.2sarge1_ sparc.deb
来源: VUPEN
名称: ADV-2006-1281
来源: SECUNIA
名称: 19559
来源: bugs.debian.org
来源: XF
名称: fbida-fbgs-tmpdir-symlink(25729)
来源: BID
名称: 17436
来源: SUSE
名称: SUSE-SR:2006:019
链接:http://www.novell.com/linux/security/advisories/2006_19_sr.html
来源: GENTOO
名称: GLSA-200604-13
链接:http://www.gentoo.org/security/en/glsa/glsa-200604-13.xml
来源: DEBIAN
名称: DSA-1068
来源: SECUNIA
名称: 21459
来源: SECUNIA
名称: 20166