dhcp-3.0.5-23.4.0.1.AXS3
エラータID: AXSA:2011-162:01
リリース日:
2011/04/21 Thursday - 14:24
題名:
dhcp-3.0.5-23.4.0.1.AXS3
影響のあるチャネル:
Asianux Server 3 for x86_64
Asianux Server 3 for x86
Severity:
High
Description:
以下項目について対処しました。<br />
<br />
[Security Fix]<br />
- ISC DHCP の dhclient は DHCP メッセージから取得したホスト名に含まれるシェルのメタキャラクタによって, リモートの攻撃者が任意のコマンドを実行することができる脆弱性があります。(CVE-2011-0997)<br />
<br />
一部CVEの翻訳文はJVNからの引用になります。<br />
http://jvndb.jvn.jp/<br />
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2011-0997
dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstrated by a hostname that is provided to dhclient-script.
dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstrated by a hostname that is provided to dhclient-script.
追加情報:
N/A
ダウンロード:
SRPMS
- dhcp-3.0.5-23.4.0.1.AXS3.src.rpm
MD5: eebc5952100db6cb97f25984c9ddfc38
SHA-256: 5e8adb910190f760ece6c83ef24ae412e1952d68650d1a9296ee5bea42bb22a9
Size: 969.57 kB
Asianux Server 3 for x86
- dhclient-3.0.5-23.4.0.1.AXS3.i386.rpm
MD5: e6f7c7ab389d2d9fe61500d4b87a6fe5
SHA-256: c303e6dc789af9e6140b7a8affb4e8b614bfe314c8821e5df2dc4d70f93d05dd
Size: 278.51 kB - dhcp-3.0.5-23.4.0.1.AXS3.i386.rpm
MD5: ecfd3cef49a826295b202533cf406363
SHA-256: 93c6b79087d993400bd159cfd824d7d127df652f0baecb3278d7478c17ab7369
Size: 869.28 kB - dhcp-devel-3.0.5-23.4.0.1.AXS3.i386.rpm
MD5: c748e2b54ac2d992dde5f1c15ac476cd
SHA-256: c9953d842e554df2889238c1f44e40687f52d1a6076236132f3a7478a9b052a9
Size: 133.10 kB - libdhcp4client-3.0.5-23.4.0.1.AXS3.i386.rpm
MD5: f2b8944cedddff73a104f0b42749bc61
SHA-256: 9ad43c9db8250e191c19054ce46f2c20324e15d1c567e2bafbe8325fe74b6fcb
Size: 245.87 kB - libdhcp4client-devel-3.0.5-23.4.0.1.AXS3.i386.rpm
MD5: 1c31e94c9b21a8104f93219ca9a0bd40
SHA-256: 880c878c4f0ff582848c7376d456837b2af91dc4997b657ba5fadf24756c3af9
Size: 379.28 kB
Asianux Server 3 for x86_64
- dhclient-3.0.5-23.4.0.1.AXS3.x86_64.rpm
MD5: df489469efe42479cc1f2833a710aaf1
SHA-256: b99c3e71221c24d0bf186331bbb998e866c2472904be1b0cd712958b91f3e24f
Size: 284.01 kB - dhcp-3.0.5-23.4.0.1.AXS3.x86_64.rpm
MD5: 870e3174e58dfe92e867c5461e20e788
SHA-256: 9b205ee0a2a1548b20dd86f3ec36f0753575dd202cadb927425bb6ec529ec4f8
Size: 885.86 kB - dhcp-devel-3.0.5-23.4.0.1.AXS3.x86_64.rpm
MD5: fa18bdce235338a8684e1bfcd9a7195f
SHA-256: abb3df350b5d784d8ab595aaa8466e9dff6d3ac6d3a916f5ceaaed9d7d0f59e4
Size: 135.79 kB - libdhcp4client-3.0.5-23.4.0.1.AXS3.x86_64.rpm
MD5: 3c27c849f6e0ef65cdfbd09077fd1600
SHA-256: 9d2f2389c9dd86c0c8ab6234486e8f1ad510d8e6d848a5f0b66b9407fbdfa73e
Size: 251.70 kB - libdhcp4client-devel-3.0.5-23.4.0.1.AXS3.x86_64.rpm
MD5: 237af3d31d16c39aac25098d22f50f5c
SHA-256: 2ef6196154f0d6fa24281331ab3b3d9b836114ef5560270f84c50b29f7aab84c
Size: 388.23 kB