openssh-5.3p1-104.AXS4
エラータID: AXSA:2014-596:02
Description :
SSH (Secure SHell) is a program for logging into and executing
commands on a remote machine. SSH is intended to replace rlogin and
rsh, and to provide secure encrypted communications between two
untrusted hosts over an insecure network. X11 connections and
arbitrary TCP/IP ports can also be forwarded over the secure channel.
OpenSSH is OpenBSD's version of the last free version of SSH, bringing
it up to date in terms of security and features.
This package includes the core files necessary for both the OpenSSH
client and server. To make this package useful, you should also
install openssh-clients, openssh-server, or both.
Security issues fixed with this release:
CVE-2014-2532
sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.
CVE-2014-2653
The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.
Fixed bugs:
* Based on the SP800-131A information security standard, the generation of a digital signature using the Digital Signature Algorithm (DSA) with the key size of 1024 bits and RSA with the key size of less than 2048 bits is disallowed after the year 2013. With this update, fixed it.
* Previously, the openssh utility incorrectly set the oom_adj value to -17 for all of its children processes. This behavior was incorrect because the children processes were supposed to have this value set to 0. With this update, fixed it.
* Previously, if the sshd service failed to verify the checksum of an installed FIPS module using the fipscheck library, the information about this failure was only provided at the standard error output of sshd. So, the user could not notice this message and be uninformed when a system had not been properly configured for FIPS mode. With this update, fixed it.
* When keys provided by the pkcs11 library were removed from the ssh agent using the "ssh-add -e" command, the user was prompted to enter a PIN. With this update, fixed it.
Enhancements:
* With this update, ControlPersist has been added to OpenSSH. The option in conjunction with the ControlMaster configuration directive specifies that the master connection remains open in the background after the initial client connection has been closed.
* When the sshd daemon is configured to force the internal SFTP session, and the user attempts to use a connection other than SFTP, the appropriate message is logged to the /var/log/secure file.
* Support for Elliptic Curve Cryptography modes for key exchange (ECDH) and host user keys (ECDSA) as specified by RFC5656 has been added to the openssh packages. However, they are not enabled by default and the user has to enable them manually.
update package.
sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.
The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.
N/A
SRPMS
- openssh-5.3p1-104.AXS4.src.rpm
MD5: 44f2aa6b044df6942526585c95361b9e
SHA-256: 39ef9f207eb5b318d4c046ee6d6f438123feedda6b789346a6a57294cd61d0d0
Size: 1.42 MB
Asianux Server 4 for x86
- openssh-5.3p1-104.AXS4.i686.rpm
MD5: 344e2499430e24612e4e8c793b8d5f48
SHA-256: ca58699accf7972888561963e22d37b333b0427921418efa49b4639c695d1fae
Size: 272.96 kB - openssh-askpass-5.3p1-104.AXS4.i686.rpm
MD5: d6195ecbdbb6af0db0a0a3c8a6b568f5
SHA-256: 8e980a06d65dd596517d05c85b81aa096669d5fb3ff7ce7d094df179207a3115
Size: 55.72 kB - openssh-clients-5.3p1-104.AXS4.i686.rpm
MD5: 30ee9d8332f4e5ad89dd897ea745052b
SHA-256: 877b26dc3266f51552a50dfedd3b5a6e74d6c4c7aeeceb382c81b5b68902fd6d
Size: 441.06 kB - openssh-server-5.3p1-104.AXS4.i686.rpm
MD5: d215fd30e79964f083a8ccff0e10fb58
SHA-256: 0aee004b76d82dc0e27863a59d9967f96bf70a890ace199f98d000aa25b670c7
Size: 318.98 kB
Asianux Server 4 for x86_64
- openssh-5.3p1-104.AXS4.x86_64.rpm
MD5: 4c3a70eca82632ff0554ab19f220b496
SHA-256: 72f089cdaafb1afab61af99941ae60f7d6b2f51a90ea84e8a0e4253c372cbd4b
Size: 270.52 kB - openssh-askpass-5.3p1-104.AXS4.x86_64.rpm
MD5: 931712de4fea04d2d6c2f7efa8d14bf5
SHA-256: 7919f42a9bf4371bc057d7a68e19734307ba8fe3fc23219c2b0caef54772035d
Size: 55.45 kB - openssh-clients-5.3p1-104.AXS4.x86_64.rpm
MD5: 68e441cbf176aa77f3de645ab626c3ed
SHA-256: 407b87e7680eddf6cec5e7f75618da24db5cb7d3709ac10ed732635422135d74
Size: 434.70 kB - openssh-server-5.3p1-104.AXS4.x86_64.rpm
MD5: a69943d8d58809f36199c8fdb9240907
SHA-256: 6bf5b3d389c8c87dc6cd361128653393dcc09268b6597e268f44ab16285dc98a
Size: 319.86 kB