WebCit Mini_Calendar组件格式串漏洞 CVE-2009-0364 CNNVD-200903-461

7.5 AV AC AU C I A
发布: 2009-03-26
修订: 2009-04-02

BUGTRAQ ID: 34206 CVE(CAN) ID: CVE-2009-0364 WebCit是Citadel邮件和协作组件所使用的基于WEB的用户界面。 webcit模块calendar_view.c文件的embeddable_mini_calendar()函数中存在格式串漏洞,远程攻击者可以通过向服务器提交特制的URL请求导致注入并执行任意指令。 Citadel/UX webcit &lt; 7.39 厂商补丁: Debian ------ Debian已经为此发布了一个安全公告(DSA-1752-1)以及相应补丁: DSA-1752-1:New webcit packages fix potential remote code execution 链接:<a href=http://www.debian.org/security/2009/dsa-1752 target=_blank rel=external nofollow>http://www.debian.org/security/2009/dsa-1752</a> 补丁下载: Source archives: <a href=http://security.debian.org/pool/updates/main/w/webcit/webcit_7.37-dfsg.orig.tar.gz target=_blank rel=external nofollow>http://security.debian.org/pool/updates/main/w/webcit/webcit_7.37-dfsg.orig.tar.gz</a> Size/MD5 checksum: 1192317 e3e47149a6553e43694e826f4885ba46 <a href=http://security.debian.org/pool/updates/main/w/webcit/webcit_7.37-dfsg-7.diff.gz target=_blank rel=external nofollow>http://security.debian.org/pool/updates/main/w/webcit/webcit_7.37-dfsg-7.diff.gz</a> Size/MD5...

0%
暂无可用Exp或PoC
当前有7条受影响产品信息