xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
English Version

GPM-Root 存在格式串漏洞


发布时间:2001-12-31
更新时间:2001-12-31
严重程度:
威胁程度:本地管理员权限
错误类型:输入验证错误
利用方式:服务器模式

受影响系统
GPM GPM 1.17.8
   + Debian Linux 2.2 68k
   + Debian Linux 2.2 alpha
   + Debian Linux 2.2 arm
   + Debian Linux 2.2 IA-32
   + Debian Linux 2.2 powerpc
   + Debian Linux 2.2 sparc
详细描述
GPM是通用鼠标协议,其中没有检查正确处理用户提供的格式串,可以导致任意代码可执行。GPM程序由ROOT权利初始化。

测试代码
尚无

解决方案
下载升级程序:

GPM GPM 1.17.8:

Debian Upgrade 2.2 alpha gpm_1.17.8-18.1_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/gpm_1.17.8-18.1_alpha.deb

Debian Upgrade 2.2 alpha libgpmg1-dev_1.17.8-18.1_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/libgpmg1-dev_1.17.8-18.1_alpha.deb

Debian Upgrade 2.2 alpha libgpmg1_1.17.8-18.1_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/libgpmg1_1.17.8-18.1_alpha.deb

Debian Upgrade 2.2 arm gpm_1.17.8-18.1_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/gpm_1.17.8-18.1_arm.deb

Debian Upgrade 2.2 arm libgpmg1-dev_1.17.8-18.1_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/libgpmg1-dev_1.17.8-18.1_arm.deb

Debian Upgrade 2.2 arm libgpmg1_1.17.8-18.1_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/libgpmg1_1.17.8-18.1_arm.deb

Debian Upgrade 2.2 i386 gpm_1.17.8-18.1_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/gpm_1.17.8-18.1_i386.deb

Debian Upgrade 2.2 i386 libgpm1-altdev_1.17.8-18.1_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/libgpm1-altdev_1.17.8-18.1_i386.deb

Debian Upgrade 2.2 i386 libgpm1_1.17.8-18.1_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/libgpm1_1.17.8-18.1_i386.deb

Debian Upgrade 2.2 i386 libgpmg1-dev_1.17.8-18.1_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/libgpmg1-dev_1.17.8-18.1_i386.deb

Debian Upgrade 2.2 i386 libgpmg1_1.17.8-18.1_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/libgpmg1_1.17.8-18.1_i386.deb

Debian Upgrade 2.2 m68k gpm_1.17.8-18.1_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/gpm_1.17.8-18.1_m68k.deb

Debian Upgrade 2.2 m68k libgpm1-altdev_1.17.8-18.1_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/libgpm1-altdev_1.17.8-18.1_m68k.deb

Debian Upgrade 2.2 m68k libgpm1_1.17.8-18.1_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/libgpm1_1.17.8-18.1_m68k.deb

Debian Upgrade 2.2 m68k libgpmg1-dev_1.17.8-18.1_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/libgpmg1-dev_1.17.8-18.1_m68k.deb

Debian Upgrade 2.2 m68k libgpmg1_1.17.8-18.1_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/libgpmg1_1.17.8-18.1_m68k.deb

Debian Upgrade 2.2 ppc gpm_1.17.8-18.1_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/gpm_1.17.8-18.1_powerpc.deb

Debian Upgrade 2.2 ppc libgpmg1-dev_1.17.8-18.1_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/libgpmg1-dev_1.17.8-18.1_powerpc.deb

Debian Upgrade 2.2 ppc libgpmg1_1.17.8-18.1_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/libgpmg1_1.17.8-18.1_powerpc.deb

Debian Upgrade 2.2 sparc gpm_1.17.8-18.1_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/gpm_1.17.8-18.1_sparc.deb

Debian Upgrade 2.2 sparc libgpmg1-dev_1.17.8-18.1_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/libgpmg1-dev_1.17.8-18.1_sparc.deb

Debian Upgrade 2.2 sparc libgpmg1_1.17.8-18.1_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/libgpmg1_1.17.8-18.1_sparc.deb

相关信息
参考:http://www.securityfocus.com/advisories/3752