ipa-3.0.0-50.2.0.1.AXS4
エラータID: AXSA:2016-660:02
Release date:
Tuesday, September 13, 2016 - 13:47
Subject:
ipa-3.0.0-50.2.0.1.AXS4
Affected Channels:
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity:
Moderate
Description:
以下項目について対処しました。
[Security Fix]
- FreeIPA の cert_revoke コマンドは,"revoke certificate" 権限をチェッ
クしておらず,"retrieve certificate" 権限を用いて,リモートの認証さ
れたユーザが任意の証明書を無効にする脆弱性があります。(CVE-2016-5404)
一部CVEの翻訳文はJVNからの引用になります。
http://jvndb.jvn.jp/
Solution:
パッケージをアップデートしてください。
CVEs:
CVE-2016-5404
The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.
The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.
Additional Info:
N/A
Download:
SRPMS
- ipa-3.0.0-50.2.0.1.AXS4.src.rpm
MD5: 222df9199a55a0d4145d9930f1e291fd
SHA-256: 34a4c94145f7125631889a6ebb5fb5e3f15aa6f91f66ccfc08f9070ea841d034
Size: 4.53 MB
Asianux Server 4 for x86
- ipa-admintools-3.0.0-50.2.0.1.AXS4.i686.rpm
MD5: 869e2ff3829c368b0c3628c89aef8af2
SHA-256: 77f628c7a70022063b002511d1e0544b228b03ebfef5f673d7e6c63fc4798fee
Size: 71.66 kB - ipa-client-3.0.0-50.2.0.1.AXS4.i686.rpm
MD5: b3df379f6983bba159f76fcce18787c0
SHA-256: e42398b0c7b7bcd39f872054f0f6267ab5b6f4fc1260cccab4c132e7f39a6730
Size: 149.98 kB - ipa-python-3.0.0-50.2.0.1.AXS4.i686.rpm
MD5: b9f744c0be27cea0e76a75cf42c9b049
SHA-256: caf195b78346cc0aee91df8a12b0faf4875bc283f1911506cbc1adc7bb9b53e0
Size: 933.06 kB - ipa-server-3.0.0-50.2.0.1.AXS4.i686.rpm
MD5: a14937d1dbfc4dc6e069d8b96615ae55
SHA-256: f3d01ef29906468804263242bc690d226489908ceb72f3c061ad9dd65ba3099f
Size: 1.10 MB - ipa-server-selinux-3.0.0-50.2.0.1.AXS4.i686.rpm
MD5: fd3a914c311abda3166aa72ebaab98bf
SHA-256: 4da54b68b7a0468343cd1949eafab5cce43a97eb23240fbc3e8b83f38cd89698
Size: 70.62 kB - ipa-server-trust-ad-3.0.0-50.2.0.1.AXS4.i686.rpm
MD5: 567a8e65a7fb18ef148be36b2bf17d87
SHA-256: f9b5c618a68f07486d7b5d013beca62b0c8045e0e07b6c17a47fef0f2873ee16
Size: 135.64 kB
Asianux Server 4 for x86_64
- ipa-admintools-3.0.0-50.2.0.1.AXS4.x86_64.rpm
MD5: 18873d1eef1203d229bd36b46774cab6
SHA-256: 935755056e7732c11a6ed6209458539635e7d6f53b5e8e93047d1ad0d3767da7
Size: 71.21 kB - ipa-client-3.0.0-50.2.0.1.AXS4.x86_64.rpm
MD5: 83d8e47ba7416aaae12c628a86087c90
SHA-256: e8a2e50f2c54d51e079491c3b549e94fe4cf0cb2fc8c0d9172f498a75346ddde
Size: 150.42 kB - ipa-python-3.0.0-50.2.0.1.AXS4.x86_64.rpm
MD5: 13edba3b7cb439d6488cec38efba7ec2
SHA-256: de390fb3b12cc045430a80fc98e9d2fec982e12ed47131ac3ab51ba7d4c22c99
Size: 932.77 kB - ipa-server-3.0.0-50.2.0.1.AXS4.x86_64.rpm
MD5: b6c87a9d0162baf0c218d7940505e355
SHA-256: 00a552fd95daecd04d4951a0da7e569f6e953ea7ca68ef3639538f3002b8caf2
Size: 1.10 MB - ipa-server-selinux-3.0.0-50.2.0.1.AXS4.x86_64.rpm
MD5: 67e5667950ee7a8a5a4112d2b9f77ff0
SHA-256: 1b6ab2a7428ba2a0ae8081dc7748ac06f9b68fb4475c075d789ec51a9ad18fc8
Size: 70.18 kB - ipa-server-trust-ad-3.0.0-50.2.0.1.AXS4.x86_64.rpm
MD5: 753f7c3dc7441c8fd45b4e17faccf7e0
SHA-256: 0a0dc8f1943844b55a1ec1690a7a7bd50d388d4d7b1ab896edc92cb7177496b7
Size: 135.91 kB