涉及程序: htdig 详细: Caldera 发布安全公告,指出 htdig 的所有版本存在漏洞,远程攻击者利用此漏洞,能以 http 服务器身份阅读服务器上的任何系统文件。 受影响系统: System Package ----------------------------------------------------------- OpenLinux 2.3 not vulnerable OpenLinux eServer 2.3.1 not vulnerable and OpenLinux eBuilder OpenLinux eDesktop 2.4 not vulnerable OpenLinux Server 3.1 All packages previous to htdig-3.1.5-8 OpenLinux Workstation 3.1 All packages previous to htdig-3.1.5-8 解决方案: 1、如果用户不需要 htdig,可以移去该软件 rpm -e htdig 2、下载安装升级版本: OpenLinux 3.1 Server 1)下载地址: ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Server/current/RPMS ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Server/current/SRPMS 2)验证: 33b12c381170e69267ffff170b5e7cdc RPMS/htdig-3.1.5-8.i386.rpm 9153eedfb420f574b846e058d198a1f1 SRPMS/htdig-3.1.5-8.src.rpm 3)安装: rpm -Fvh htdig-3.1.5-8.i386.rpm OpenLinux 3.1 Workstation 下载地址: ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Workstation/current/RPMS