积极预防 及时发现
快速响应 力保恢复
本地用户利用 SENDFILED 漏洞能以 root 权限执行任意代码
发布时间:2001-04-23 信息来源:管理员

涉及程序: SENDFILED 详细: DEBIAN 今天发布安全公告,指出 SAFT 守护进程 "SENDFILED" 存在安全漏洞。本地用户利用此漏洞能在 root 权限下执行任意代码。DEBIAN 建议用户立即升级 SENDFILE 软件包。 受影响系统: SENDFILE 解决方案: 请用户参考下列步骤升级该软件包: 1、取得软件包: wget url 2、安装相关文件:dpkg -i file.deb 3、软件包下载点: Source archives: http://security.debian.org/dists/stable/updates/main/source/sendfile_2.1-20.2.diff.gz MD5 checksum: b5ba5230deef00b0cf815cb79edd5033 http://security.debian.org/dists/stable/updates/main/source/sendfile_2.1-20.2.dsc MD5 checksum: 48e5cc3435e2432e41299c31bb08f1a4 http://security.debian.org/dists/stable/updates/main/source/sendfile_2.1.orig.tar.gz MD5 checksum: cff003126595d8e77143c42ef898dc10 Alpha architecture: http://security.debian.org/dists/stable/updates/main/binary-alpha/sendfile_2.1-20.2_alpha.deb MD5 checksum: df6c0c2d24eeb20d8d4ca7ccce295f4f ARM architecture: http://security.debian.org/dists/stable/updates/main/binary-arm/sendfile_2.1-20.2_arm.deb MD5 checksum: cecd8e7489dfc4b663e3d99e63d8b086 Intel ia32 architecture: http://security.debian.org/dists/stable/updates/main/binary-i386/sendfile_2.1-20.2_i386.deb MD5 checksum: e519872a28daeb614e235650b7cd88bd Motorola 680x0 architecture: http://security.debian.org/dists/stable/updates/main/binary-m68k/sendfile_2.1-20.2_m68k.deb MD5 checksum: 313aa66e64c0509c041ff58a29be6c86 PowerPC architecture: http://security.debian.org/dists/stable/updates/main/binary-powerpc/sendfile_2.1-20.2_powerpc.deb MD5 checksum: a2d2a9829642c9d20efeb5443d17990c Sun Sparc architecture: http://security.debian.org/dists/stable/updates/main/binary-sparc/sendfile_2.1-20.2_sparc.deb MD5 checksum: 0e9722314cc01e8d0ad47781c1d0964c 注意:这些文件将会被移往: ftp://ftp.debian.org/debian/dists/stable/*/binary-$arch/