安全研究

安全漏洞
Dell OpenManage Web Server POST请求堆溢出漏洞

发布日期:2004-02-26
更新日期:2009-07-12

受影响系统:
Dell OpenManage 3.7.1
Dell OpenManage 3.7
Dell OpenManage 3.4
Dell OpenManage 3.2
描述:
BUGTRAQ  ID: 9750
CVE(CAN) ID: CVE-2004-0331

Dell OpenManage Server Administrator (OMSA)可帮助管理员有效地管理他们的服务器。

Dell OpenManage Web Server 3.4.0存在堆缓冲区溢出漏洞,远程攻击者通过带较长应用变量的HTTP POST,利用此漏洞可造成拒绝服务。

<*来源:wirepair (wirepair@roguemail.net
  
  链接:http://xforce.iss.net/xforce/xfdb/15325
*>

建议:
厂商补丁:

Dell
----
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:

http://www.dell.com/support/drivers/us/en/

Dell OpenManage 3.2
Dell SA_Security_Patch_LX_A01.tar.gz
Linux Platforms
http://support.dell.com/filelib/Format.aspx?ReleaseID=R74030

Dell SA_Security_Patch_NW_A01.exe
Netware Platforms
http://support.dell.com/filelib/Format.aspx?ReleaseID=R74031

Dell SA_Security_Patch_WIN_A01.exe
http://support.dell.com/filelib/exportcompliance.aspx?FileID=96563&Rel easeID=R74029&location=1&st=

Dell SA_Security_Patch_WIN_A01.exe
Microsoft Windows Platforms
http://support.dell.com/filelib/Format.aspx?ReleaseID=R74029


Dell OpenManage 3.4
Dell SA_Security_Patch_LX_A01.tar.gz
Linux Platforms
http://support.dell.com/filelib/Format.aspx?ReleaseID=R74030

Dell SA_Security_Patch_NW_A01.exe
Netware Platforms
http://support.dell.com/filelib/Format.aspx?ReleaseID=R74031

Dell SA_Security_Patch_WIN_A01.exe
http://support.dell.com/filelib/exportcompliance.aspx?FileID=96563&Rel easeID=R74029&location=1&st=

Dell SA_Security_Patch_WIN_A01.exe
Microsoft Windows Platforms
http://support.dell.com/filelib/Format.aspx?ReleaseID=R74029


Dell OpenManage 3.7
Dell SA_Security_Patch_LX_A01.tar.gz
Linux Platforms
http://support.dell.com/filelib/Format.aspx?ReleaseID=R74030

Dell SA_Security_Patch_NW_A01.exe
Netware Platforms
http://support.dell.com/filelib/Format.aspx?ReleaseID=R74031

Dell SA_Security_Patch_WIN_A01.exe
http://support.dell.com/filelib/exportcompliance.aspx?FileID=96563&Rel easeID=R74029&location=1&st=

Dell SA_Security_Patch_WIN_A01.exe
Microsoft Windows Platforms
http://support.dell.com/filelib/Format.aspx?ReleaseID=R74029


Dell OpenManage 3.7.1
Dell SA_Security_Patch_LX_A01.tar.gz
Linux Platforms
http://support.dell.com/filelib/Format.aspx?ReleaseID=R74030

Dell SA_Security_Patch_NW_A01.exe
Netware Platforms
http://support.dell.com/filelib/Format.aspx?ReleaseID=R74031

Dell SA_Security_Patch_WIN_A01.exe
http://support.dell.com/filelib/exportcompliance.aspx?FileID=96563&Rel easeID=R74029&location=1&st=

Dell SA_Security_Patch_WIN_A01.exe
Microsoft Windows Platforms
http://support.dell.com/filelib/Format.aspx?ReleaseID=R74029

浏览次数:1981
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障