CVE-2005-3123
CVSS5.0
发布时间 :2005-10-30 15:02:00
修订时间 :2011-03-07 21:25:50
NMCOPS    

[原文]Directory traversal vulnerability in GNUMP3D before 2.9.6 allows remote attackers to read arbitrary files via crafted sequences such as "/.//..//////././", which is collapsed into "/.././" after ".." and "//" sequences are removed.


[CNNVD]GNU gnump3d 目录遍历漏洞(CNNVD-200510-260)

        GNU MP3 Daemon(gnump3d)是一个小巧轻便的流媒体服务器,支持MP3、OGG以及其他音频文件。
        GNU gnump3d中存在目录遍历漏洞,攻击者可以利用特制的URL读取流媒体服务器用户可以访问的任意文件。

- CVSS (基础分值)

CVSS分值: 5 [中等(MEDIUM)]
机密性影响: PARTIAL [很可能造成信息泄露]
完整性影响: NONE [不会对系统完整性产生影响]
可用性影响: NONE [对系统可用性无影响]
攻击复杂度: LOW [漏洞利用没有访问限制 ]
攻击向量: [--]
身份认证: NONE [漏洞利用无需身份认证]

- CPE (受影响的平台与产品)

cpe:/a:gnu:gnump3d:2.9.3GNU GNUMP3D 2.9.3
cpe:/a:gnu:gnump3d:2.9.2GNU GNUMP3D 2.9.2
cpe:/a:gnu:gnump3d:2.9GNU GNUMP3D 2.9
cpe:/a:gnu:gnump3d:2.9.5GNU GNUMP3D 2.9.5
cpe:/a:gnu:gnump3d:2.9.1GNU GNUMP3D 2.9.1
cpe:/a:gnu:gnump3d:2.9.4GNU GNUMP3D 2.9.4

- OVAL (用于检测的技术细节)

未找到相关OVAL定义

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3123
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2005-3123
(官方数据源) NVD
http://www.cnnvd.org.cn/vulnerability/show/cv_cnnvdid/CNNVD-200510-260
(官方数据源) CNNVD

- 其它链接及资源

http://www.securityfocus.com/bid/15228
(PATCH)  BID  15228
http://www.debian.org/security/2005/dsa-877
(VENDOR_ADVISORY)  DEBIAN  DSA-877
http://secunia.com/advisories/17351
(VENDOR_ADVISORY)  SECUNIA  17351
http://lists.gnu.org/archive/html/gnump3d-users/2005-10/msg00013.html
(PATCH)  MLIST  [Gnump3d-users] 20051028 New release - security fixes.
http://www.vupen.com/english/advisories/2005/2242
(UNKNOWN)  VUPEN  ADV-2005-2242
http://www.osvdb.org/20360
(UNKNOWN)  OSVDB  20360
http://www.novell.com/linux/security/advisories/2005_28_sr.html
(UNKNOWN)  SUSE  SUSE-SR:2005:028
http://securitytracker.com/id?1015118
(UNKNOWN)  SECTRACK  1015118
http://secunia.com/advisories/17559
(VENDOR_ADVISORY)  SECUNIA  17559
http://www.novell.com/linux/security/advisories/2005_27_sr.html
(UNKNOWN)  SUSE  SUSE-SR:2005:027
http://securityreason.com/securityalert/127
(UNKNOWN)  SREASON  127

- 漏洞信息

GNU gnump3d 目录遍历漏洞
中危 路径遍历
2005-10-30 00:00:00 2006-06-13 00:00:00
远程  
        GNU MP3 Daemon(gnump3d)是一个小巧轻便的流媒体服务器,支持MP3、OGG以及其他音频文件。
        GNU gnump3d中存在目录遍历漏洞,攻击者可以利用特制的URL读取流媒体服务器用户可以访问的任意文件。

- 公告与补丁

        暂无数据

- 漏洞信息 (F41359)

Gentoo Linux Security Advisory 200511-5 (PacketStormID:F41359)
2005-11-08 00:00:00
Gentoo  security.gentoo.org
advisory,xss
linux,gentoo
CVE-2005-3424,CVE-2005-3425,CVE-2005-3123
[点击下载]

Gentoo Linux Security Advisory GLSA 200511-05 - Steve Kemp reported about two cross-site scripting attacks that are related to the handling of files. Also reported is a directory traversal vulnerability which comes from the attempt to sanitize input paths. Versions less than 2.9.7 are affected.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200511-05
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: Normal
     Title: GNUMP3d: Directory traversal and XSS vulnerabilities
      Date: November 06, 2005
      Bugs: #109667
        ID: 200511-05

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

GNUMP3d is vulnerable to directory traversal and cross-site scripting
attacks that may result in information disclosure or the compromise of
a browser.

Background
==========

GNUMP3d is a streaming server for MP3s, OGG vorbis files, movies and
other media formats.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /  Vulnerable  /                  Unaffected
    -------------------------------------------------------------------
  1  media-sound/gnump3d       < 2.9.7                        >= 2.9.7

Description
===========

Steve Kemp reported about two cross-site scripting attacks that are
related to the handling of files (CVE-2005-3424, CVE-2005-3425). Also
reported is a directory traversal vulnerability which comes from the
attempt to sanitize input paths (CVE-2005-3123).

Impact
======

A remote attacker could exploit this to disclose sensitive information
or inject and execute malicious script code, potentially compromising
the victim's browser.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All GNUMP3d users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=media-sound/gnump3d-2.9.7"

References
==========

  [ 1 ] CVE-2005-3123
        http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3123
  [ 2 ] CVE-2005-3424
        http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3424
  [ 3 ] CVE-2005-3425
        http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3425

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

  http://security.gentoo.org/glsa/glsa-200511-05.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org.

License
=======

Copyright 2005 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0
    

- 漏洞信息 (F41059)

Debian Linux Security Advisory 877-1 (PacketStormID:F41059)
2005-10-30 00:00:00
Debian  security.debian.org
advisory,arbitrary,javascript,vulnerability
linux,debian
CVE-2005-3122,CVE-2005-3123
[点击下载]

Debian Security Advisory DSA 877-1 - Steve Kemp discovered two vulnerabilities in gnump3d, a streaming server for MP3 and OGG files. The 404 error page does not strip malicious javascript content from the resulting page, which would be executed in the victims browser. By using specially crafting URLs it is possible to read arbitrary files to which the user of the streaming server has access to.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 877-1                     security@debian.org
http://www.debian.org/security/                             Martin Schulze
October 28th, 2005                      http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package        : gnump3d
Vulnerability  : cross-site scripting, directory traversal
Problem type   : remote
Debian-specific: no
CVE ID         : CVE-2005-3122 CVE-2005-3123

Steve Kemp discovered two vulnerabilities in gnump3d, a streaming
server for MP3 and OGG files.  The Common Vulnerabilities and
Exposures Project identifies the following problems:

CVE-2005-3122

    The 404 error page does not strip malicious javascript content
    from the resulting page, which would be executed in the victims
    browser.

CVE-2005-3123

    By using specially crafting URLs it is possible to read arbitary
    files to which the user of the streaming server has access to.

The old stable distribution (woody) does not contain a gnump3d package.

For the stable distribution (sarge) these problems have been fixed in
version 2.9.3-1sarge2.

For the unstable distribution (sid) these problems have been fixed in
version 2.9.6-1.

We recommend that you upgrade your gnump3d package.


Upgrade Instructions
- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.1 alias sarge
- --------------------------------

  Source archives:

    http://security.debian.org/pool/updates/main/g/gnump3d/gnump3d_2.9.3-1sarge2.dsc
      Size/MD5 checksum:      575 16114607fe426691518743a80a15deda
    http://security.debian.org/pool/updates/main/g/gnump3d/gnump3d_2.9.3.orig.tar.gz
      Size/MD5 checksum:   616250 1a0d6a10f6ac2354e1f8c6000665f299
    http://security.debian.org/pool/updates/main/g/gnump3d/gnump3d_2.9.3-1sarge2.diff.gz
      Size/MD5 checksum:    14298 9fbb9305ab4282b7957be8203dd6fb35

  Architecture independent components:

    http://security.debian.org/pool/updates/main/g/gnump3d/gnump3d_2.9.3-1sarge2_all.deb
      Size/MD5 checksum:   603662 a94ff8504be400030a5f5fdb08987da0


  These files will probably be moved into the stable distribution on
  its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQFDYfRjW5ql+IAeqTIRAiSQAJ9J3KU5U/TV0XK6xPLNXlY8E9nhXgCeIKQI
KQjf5W+ekqi1NjEw71BXrLE=
=Je47
-----END PGP SIGNATURE-----

    

- 漏洞信息

20360
GNUMP3d Server Traversal Arbitrary File Access
Remote / Network Access Input Manipulation
Loss of Confidentiality
Exploit Public

- 漏洞描述

GNUMP3d contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the program not properly sanitizing user input, specifically traversal style attacks (../../).

- 时间线

2005-10-28 Unknow
2005-10-28 Unknow

- 解决方案

Upgrade to version 2.9.6 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

- 相关参考

- 漏洞作者

- 漏洞信息

GNU gnump3d Directory Traversal Vulnerability
Input Validation Error 15228
Yes No
2005-10-28 12:00:00 2005-10-28 12:00:00
Discovery credited to Steve Kemp.

- 受影响的程序版本

SuSE SUSE Linux Enterprise Server 8
+ Linux kernel 2.4.21
+ Linux kernel 2.4.19
S.u.S.E. SuSE Linux Standard Server 8.0
S.u.S.E. SuSE Linux School Server for i386
S.u.S.E. SUSE LINUX Retail Solution 8.0
S.u.S.E. SuSE Linux Openexchange Server 4.0
S.u.S.E. Open-Enterprise-Server 9.0
S.u.S.E. Novell Linux Desktop 9.0
S.u.S.E. Linux Professional 10.0 OSS
S.u.S.E. Linux Professional 10.0
S.u.S.E. Linux Professional 9.3 x86_64
S.u.S.E. Linux Professional 9.3
S.u.S.E. Linux Professional 9.2 x86_64
S.u.S.E. Linux Professional 9.2
S.u.S.E. Linux Professional 9.1 x86_64
S.u.S.E. Linux Professional 9.1
S.u.S.E. Linux Professional 9.0 x86_64
S.u.S.E. Linux Professional 9.0
S.u.S.E. Linux Professional 8.2
S.u.S.E. Linux Personal 10.0 OSS
S.u.S.E. Linux Personal 9.3 x86_64
S.u.S.E. Linux Personal 9.3
S.u.S.E. Linux Personal 9.2 x86_64
S.u.S.E. Linux Personal 9.2
S.u.S.E. Linux Personal 9.1 x86_64
S.u.S.E. Linux Personal 9.1
S.u.S.E. Linux Personal 9.0 x86_64
S.u.S.E. Linux Personal 9.0
S.u.S.E. Linux Personal 8.2
S.u.S.E. Linux Openexchange Server
S.u.S.E. Linux Enterprise Server 9
S.u.S.E. Linux Desktop 1.0
GNU gnump3d 2.9.5
+ Gentoo Linux
GNU gnump3d 2.9.4
GNU gnump3d 2.9.3
GNU gnump3d 2.9.2
GNU gnump3d 2.9.1
GNU gnump3d 2.9
Debian Linux 3.1 sparc
Debian Linux 3.1 s/390
Debian Linux 3.1 ppc
Debian Linux 3.1 mipsel
Debian Linux 3.1 mips
Debian Linux 3.1 m68k
Debian Linux 3.1 ia-64
Debian Linux 3.1 ia-32
Debian Linux 3.1 hppa
Debian Linux 3.1 arm
Debian Linux 3.1 amd64
Debian Linux 3.1 alpha
Debian Linux 3.1
GNU gnump3d 2.9.6

- 不受影响的程序版本

GNU gnump3d 2.9.6

- 漏洞讨论

GNU gnump3d is prone to a directory traversal vulnerability. Information obtained may be used in further attacks.

- 漏洞利用

An exploit is not required.

- 解决方案

Debian has released advisory DSA 877-1 and fixes to address this issue. Please see the referenced advisory for further information.

SUSE has released advisory SUSE-SR:2005:025 to address this, and other issues in various packages, in various SUSE products. The advisory states that there are pending fixes for this issue in SUSE products. Please see the referenced advisory for further information.

Gentoo has released advisory GLSA 200511-05 to address this issue. Gentoo updates may be applied by running the following commands as the superuser:

emerge --sync
emerge --ask --oneshot --verbose ">=media-sound/gnump3d-2.9.7"

SUSE has released advisory SUSE-SR:2005:027 to address this, and other issues in various packages, in various SUSE products. The advisory states that there are pending fixes for this issue in SUSE products. Please see the referenced advisory for further information.

SUSE advisory SUSE-SR:2005:028 is available to address various issues. Please see the referenced advisory for more information.

A fix is available:


GNU gnump3d 2.9

GNU gnump3d 2.9.1

GNU gnump3d 2.9.2

GNU gnump3d 2.9.3

GNU gnump3d 2.9.4

GNU gnump3d 2.9.5

- 相关参考

 

 

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站