CVE-2005-3350
CVSS7.5
发布时间 :2005-11-03 19:02:00
修订时间 :2011-03-07 21:26:23
NMCOS    

[原文]libungif library before 4.1.0 allows attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an out-of-bounds write.


[CNNVD]Libungif GIF文件边界溢出执行任意代码漏洞(CNNVD-200511-107)

        libungif是一套可以方便的把GIF文件加入到程序中进行管理的库。
        libungif4.1.0之前的程序库可让攻击者通过特制GIF文件来毁坏内存,导致写入边界溢出,并可能执行任意代码。

- CVSS (基础分值)

CVSS分值: 7.5 [严重(HIGH)]
机密性影响: PARTIAL [很可能造成信息泄露]
完整性影响: PARTIAL [可能会导致系统文件被修改]
可用性影响: PARTIAL [可能会导致性能下降或中断资源访问]
攻击复杂度: LOW [漏洞利用没有访问限制 ]
攻击向量: [--]
身份认证: NONE [漏洞利用无需身份认证]

- CPE (受影响的平台与产品)

cpe:/a:libungif:libungif:4.1
cpe:/a:libungif:libungif:4.1.3

- OVAL (用于检测的技术细节)

oval:org.mitre.oval:def:9314libungif library before 4.1.0 allows attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an...
oval:org.mitre.oval:def:21867ELSA-2009:0444: giflib security update (Important)
*OVAL详细的描述了检测该漏洞的方法,你可以从相关的OVAL定义中找到更多检测该漏洞的技术细节。

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3350
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2005-3350
(官方数据源) NVD
http://www.cnnvd.org.cn/vulnerability/show/cv_cnnvdid/CNNVD-200511-107
(官方数据源) CNNVD

- 其它链接及资源

https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00771.html
(UNKNOWN)  FEDORA  FEDORA-2009-5118
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=171413
(UNKNOWN)  CONFIRM  https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=171413
http://www.vupen.com/english/advisories/2005/2295
(UNKNOWN)  VUPEN  ADV-2005-2295
http://www.redhat.com/support/errata/RHSA-2009-0444.html
(UNKNOWN)  REDHAT  RHSA-2009:0444
http://www.redhat.com/support/errata/RHSA-2005-828.html
(VENDOR_ADVISORY)  REDHAT  RHSA-2005:828
http://secunia.com/advisories/35164
(UNKNOWN)  SECUNIA  35164
http://secunia.com/advisories/34872
(UNKNOWN)  SECUNIA  34872
http://www.ubuntulinux.org/usn/usn-214-1
(UNKNOWN)  UBUNTU  USN-214-1
http://www.securityfocus.com/bid/15299
(UNKNOWN)  BID  15299
http://www.securityfocus.com/archive/1/archive/1/428059/30/6300/threaded
(UNKNOWN)  FEDORA  FLSA-2006:174479
http://www.securityfocus.com/archive/1/archive/1/428059/100/0/threaded
(UNKNOWN)  FEDORA  FLSA:174479
http://www.osvdb.org/20471
(UNKNOWN)  OSVDB  20471
http://www.mandriva.com/security/advisories?name=MDKSA-2005:207
(UNKNOWN)  MANDRIVA  MDKSA-2005:207
http://www.gentoo.org/security/en/glsa/glsa-200511-03.xml
(UNKNOWN)  GENTOO  GLSA-200511-03
http://www.debian.org/security/2005/dsa-890
(UNKNOWN)  DEBIAN  DSA-890
http://sourceforge.net/project/shownotes.php?release_id=364493
(UNKNOWN)  CONFIRM  http://sourceforge.net/project/shownotes.php?release_id=364493
http://securitytracker.com/id?1015149
(UNKNOWN)  SECTRACK  1015149
http://secunia.com/advisories/17559
(UNKNOWN)  SECUNIA  17559
http://secunia.com/advisories/17508
(UNKNOWN)  SECUNIA  17508
http://secunia.com/advisories/17497
(UNKNOWN)  SECUNIA  17497
http://secunia.com/advisories/17488
(UNKNOWN)  SECUNIA  17488
http://secunia.com/advisories/17482
(UNKNOWN)  SECUNIA  17482
http://secunia.com/advisories/17462
(UNKNOWN)  SECUNIA  17462
http://secunia.com/advisories/17442
(UNKNOWN)  SECUNIA  17442
http://secunia.com/advisories/17438
(UNKNOWN)  SECUNIA  17438
http://secunia.com/advisories/17436
(UNKNOWN)  SECUNIA  17436
http://scary.beasts.org/security/CESA-2005-007.txt
(UNKNOWN)  MISC  http://scary.beasts.org/security/CESA-2005-007.txt
http://bugs.gentoo.org/show_bug.cgi?id=109997
(UNKNOWN)  MISC  http://bugs.gentoo.org/show_bug.cgi?id=109997

- 漏洞信息

Libungif GIF文件边界溢出执行任意代码漏洞
高危 其他
2005-11-03 00:00:00 2009-05-27 00:00:00
远程  
        libungif是一套可以方便的把GIF文件加入到程序中进行管理的库。
        libungif4.1.0之前的程序库可让攻击者通过特制GIF文件来毁坏内存,导致写入边界溢出,并可能执行任意代码。

- 公告与补丁

        暂无数据

- 漏洞信息

20471
libungif/giflib GIF File Handling Out-of-bounds Read Arbitrary Code Execution
Context Dependent Input Manipulation
Loss of Integrity Upgrade
Exploit Unknown Vendor Verified

- 漏洞描述

libungif and giflib contain a flaw in the handling of colormaps in GIF files. The issue is due to the libraries not validating user-supplied input. With a specially crafted GIF file containing a malformed colormap, a context-dependent attacker can cause a denial of service or potentially execute arbitrary code.

- 时间线

2005-11-04 Unknow
Unknow 2005-10-19

- 解决方案

It has been reported that this issue has been fixed. Upgrade to version 4.1.4, or higher, to address this vulnerability.

- 相关参考

- 漏洞作者

- 漏洞信息

Libungif Null Pointer Dereference Denial of Service Vulnerability
Failure to Handle Exceptional Conditions 15304
Yes No
2005-11-03 12:00:00 2009-06-22 05:50:00
Daniel Eisenbud and Chris Evans are credited with the discovery of this vulnerability.

- 受影响的程序版本

Ubuntu Ubuntu Linux 5.10 powerpc
Ubuntu Ubuntu Linux 5.10 i386
Ubuntu Ubuntu Linux 5.10 amd64
Ubuntu Ubuntu Linux 5.0 4 powerpc
Ubuntu Ubuntu Linux 5.0 4 i386
Ubuntu Ubuntu Linux 5.0 4 amd64
Ubuntu Ubuntu Linux 4.1 ppc
Ubuntu Ubuntu Linux 4.1 ia64
Ubuntu Ubuntu Linux 4.1 ia32
SuSE SUSE Linux Enterprise Server 8
+ Linux kernel 2.4.21
+ Linux kernel 2.4.19
SGI ProPack 3.0 SP6
S.u.S.E. SuSE Linux Standard Server 8.0
S.u.S.E. SuSE Linux School Server for i386
S.u.S.E. SUSE LINUX Retail Solution 8.0
S.u.S.E. SuSE Linux Openexchange Server 4.0
S.u.S.E. Open-Enterprise-Server 9.0
S.u.S.E. Novell Linux Desktop 9.0
S.u.S.E. Linux Professional 10.0 OSS
S.u.S.E. Linux Professional 10.0
S.u.S.E. Linux Professional 9.3 x86_64
S.u.S.E. Linux Professional 9.3
S.u.S.E. Linux Professional 9.2 x86_64
S.u.S.E. Linux Professional 9.2
S.u.S.E. Linux Professional 9.1 x86_64
S.u.S.E. Linux Professional 9.1
S.u.S.E. Linux Professional 9.0 x86_64
S.u.S.E. Linux Professional 9.0
S.u.S.E. Linux Professional 8.2
S.u.S.E. Linux Personal 10.0 OSS
S.u.S.E. Linux Personal 9.3 x86_64
S.u.S.E. Linux Personal 9.3
S.u.S.E. Linux Personal 9.2 x86_64
S.u.S.E. Linux Personal 9.2
S.u.S.E. Linux Personal 9.1 x86_64
S.u.S.E. Linux Personal 9.1
S.u.S.E. Linux Personal 9.0 x86_64
S.u.S.E. Linux Personal 9.0
S.u.S.E. Linux Personal 8.2
S.u.S.E. Linux Enterprise Server 9
S.u.S.E. Linux Desktop 1.0
RedHat Linux 9.0 i386
RedHat Linux 7.3 i386
RedHat Enterprise Linux WS 4
RedHat Enterprise Linux WS 3
RedHat Enterprise Linux WS 2.1 IA64
RedHat Enterprise Linux WS 2.1
RedHat Enterprise Linux ES 4
RedHat Enterprise Linux ES 3
RedHat Enterprise Linux ES 2.1 IA64
RedHat Enterprise Linux ES 2.1
RedHat Enterprise Linux Desktop Workstation 5 client
RedHat Desktop 4.0
RedHat Desktop 3.0
RedHat Advanced Workstation for the Itanium Processor 2.1 IA64
RedHat Advanced Workstation for the Itanium Processor 2.1
Red Hat Fedora Core2
Red Hat Fedora Core1
Red Hat Fedora 9
Red Hat Fedora 10
Red Hat Enterprise Linux Desktop 5 client
Red Hat Enterprise Linux AS 4
Red Hat Enterprise Linux AS 3
Red Hat Enterprise Linux AS 2.1 IA64
Red Hat Enterprise Linux AS 2.1
Red Hat Enterprise Linux 5 Server
Mandriva Linux Mandrake 2006.0 x86_64
Mandriva Linux Mandrake 2006.0
Mandriva Linux Mandrake 10.2 x86_64
Mandriva Linux Mandrake 10.2
Mandriva Linux Mandrake 10.1 x86_64
Mandriva Linux Mandrake 10.1
MandrakeSoft Corporate Server 3.0 x86_64
MandrakeSoft Corporate Server 3.0
MandrakeSoft Corporate Server 2.1 x86_64
MandrakeSoft Corporate Server 2.1
libungif libungif 4.1.3
+ Red Hat Fedora Core4
+ Red Hat Fedora Core3
libungif libungif 4.1.2
libungif libungif 4.1
libungif giflib 4.1.3
Gentoo Linux
Debian Linux 3.1 sparc
Debian Linux 3.1 s/390
Debian Linux 3.1 ppc
Debian Linux 3.1 mipsel
Debian Linux 3.1 mips
Debian Linux 3.1 m68k
Debian Linux 3.1 ia-64
Debian Linux 3.1 ia-32
Debian Linux 3.1 hppa
Debian Linux 3.1 arm
Debian Linux 3.1 amd64
Debian Linux 3.1 alpha
Debian Linux 3.1
Debian Linux 3.0 sparc
Debian Linux 3.0 s/390
Debian Linux 3.0 ppc
Debian Linux 3.0 mipsel
Debian Linux 3.0 mips
Debian Linux 3.0 m68k
Debian Linux 3.0 ia-64
Debian Linux 3.0 ia-32
Debian Linux 3.0 hppa
Debian Linux 3.0 arm
Debian Linux 3.0 alpha
Debian Linux 3.0
Conectiva Linux 10.0
libungif libungif 4.1.4
libungif giflib 4.1.4

- 不受影响的程序版本

libungif libungif 4.1.4
libungif giflib 4.1.4

- 漏洞讨论

The 'libungif' library is prone to a denial-of-service vulnerability because it fails to handle exceptional conditions.

Successful exploitation of this vulnerability will cause the application using the affected library to crash, effectively denying service to legitimate users.

This issue affects libungif 4.1.3 and earlier.

- 漏洞利用

Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: vuldb@securityfocus.com.

- 解决方案

Vendor updates are available. Please see the references for more information.


libungif libungif 4.1

libungif libungif 4.1.2

libungif libungif 4.1.3

libungif giflib 4.1.3

- 相关参考

 

 

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站