util-linux-ng-2.17.2-12.4.AXS4
エラータID: AXSA:2012-06:01
リリース日:
2012/01/11 Wednesday - 16:11
題名:
util-linux-ng-2.17.2-12.4.AXS4
影響のあるチャネル:
Asianux Server 4 for x86
Asianux Server 4 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- util-linux の mount は リソースの制限が干渉するかどうかを最初にチェックせず,/etc/mtab.tmp ファイルを追加しようとし, 小さいRLIMIT_FSIZE の値で処理することによって,ローカルのユーザが /etc/mtab ファイルの破損を引き起こす脆弱性があります。(CVE-2011-1675)
- util-linux の mount は マウントエントリを追加しようとして失敗した後に,/etc/mtab~ ロックファイルを削除することができないために詳細不明な影響があります。(CVE-2011-1677)
一部CVEの翻訳文はJVNからの引用になります。
http://jvndb.jvn.jp
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2011-1675
mount in util-linux 2.19 and earlier attempts to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
mount in util-linux 2.19 and earlier attempts to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
CVE-2011-1677
mount in util-linux 2.19 and earlier does not remove the /etc/mtab~ lock file after a failed attempt to add a mount entry, which has unspecified impact and local attack vectors.
mount in util-linux 2.19 and earlier does not remove the /etc/mtab~ lock file after a failed attempt to add a mount entry, which has unspecified impact and local attack vectors.
追加情報:
N/A
ダウンロード:
SRPMS
- util-linux-ng-2.17.2-12.4.AXS4.src.rpm
MD5: 4ce36d67af5443f8a9c1b7fb2fc2068d
SHA-256: aa106fec678373a213b585bed047df7cccb2fdbc9ba43f10c2d8a6a7517a66f2
Size: 4.24 MB
Asianux Server 4 for x86
- libblkid-2.17.2-12.4.AXS4.i686.rpm
MD5: e67be1d09709d7e57d7474952626c03f
SHA-256: 215e653d3ddb17d2da7afbf47fe4c7372273cfaedc9338612544a03ad48c18be
Size: 115.43 kB - libblkid-devel-2.17.2-12.4.AXS4.i686.rpm
MD5: 3706df855334a23ebf9b0458254b3c84
SHA-256: 4a0245ed3365bb5957743ebd2ccf6d7ed9da00de21d36990bba6d4332d56b464
Size: 134.74 kB - libuuid-2.17.2-12.4.AXS4.i686.rpm
MD5: 41b04a78e638e2e9534cbc156da5a3d9
SHA-256: 3b819fe879a79904dcc6db226abba767ca1213f3e59a69a97f7f4c084cf01f80
Size: 64.71 kB - libuuid-devel-2.17.2-12.4.AXS4.i686.rpm
MD5: 2f6178323c04e8e741cb8acaa280619b
SHA-256: 62c6b43d270276c3bae225eec353fc79aa8958e1411a0abda201dc63101de32c
Size: 80.32 kB - util-linux-ng-2.17.2-12.4.AXS4.i686.rpm
MD5: f0568a44cea8e754024ea2add59515d5
SHA-256: 359ceee0ca8d90c09aaa0f705b467865684dc034b5e13ca497cca6cd41f3a6bf
Size: 1.51 MB - uuidd-2.17.2-12.4.AXS4.i686.rpm
MD5: a3f7ef7b5aaecf3f93ce2375eaf9f6d1
SHA-256: 9d0b9974b674bfd3c930fcf899ea8540ddc3e761c1ff32feb18b0c33909edd62
Size: 65.50 kB
Asianux Server 4 for x86_64
- libblkid-2.17.2-12.4.AXS4.x86_64.rpm
MD5: 6306aada382b778fddad3180a28b9916
SHA-256: 7c008cf7ca642aa1fb043a1e26bbca43f844613b882bfef91fe85222c1e68711
Size: 110.38 kB - libblkid-devel-2.17.2-12.4.AXS4.x86_64.rpm
MD5: 0b5686d502d80fa6f13bef78b53b8c89
SHA-256: 179ec3448bdec0ce50c6b0664383b59d57039bbf1bde40e094b64b16a46ec5ee
Size: 130.02 kB - libuuid-2.17.2-12.4.AXS4.x86_64.rpm
MD5: 2d0a38943e1b25a78e9dc4bf40d62a4c
SHA-256: e4216e0249369dbb4f9f24d2f76fd215e7ef284ad97555ef04438c2e45b46242
Size: 63.77 kB - libuuid-devel-2.17.2-12.4.AXS4.x86_64.rpm
MD5: 2205cffaf092e7644f8f0c77a1cbb59f
SHA-256: b51c140897feee5dbfa7e55aa95e3edad7c5fddc2af21a7ef0e15752a1705845
Size: 80.20 kB - util-linux-ng-2.17.2-12.4.AXS4.x86_64.rpm
MD5: 6bf900133cde368d3875a8dd28944669
SHA-256: b76a2c7388df1cd8f10f4ca31e914324cff20ef202deac0653130d67f65546e3
Size: 1.51 MB - uuidd-2.17.2-12.4.AXS4.x86_64.rpm
MD5: 33bb9e691228a3f910b6f54292cbe287
SHA-256: f63dd0e0258ac8a755bb7c17475e0db901d816643dac2501230fc4d437daa918
Size: 65.16 kB - libblkid-2.17.2-12.4.AXS4.i686.rpm
MD5: e67be1d09709d7e57d7474952626c03f
SHA-256: 215e653d3ddb17d2da7afbf47fe4c7372273cfaedc9338612544a03ad48c18be
Size: 115.43 kB - libblkid-devel-2.17.2-12.4.AXS4.i686.rpm
MD5: 3706df855334a23ebf9b0458254b3c84
SHA-256: 4a0245ed3365bb5957743ebd2ccf6d7ed9da00de21d36990bba6d4332d56b464
Size: 134.74 kB - libuuid-2.17.2-12.4.AXS4.i686.rpm
MD5: 41b04a78e638e2e9534cbc156da5a3d9
SHA-256: 3b819fe879a79904dcc6db226abba767ca1213f3e59a69a97f7f4c084cf01f80
Size: 64.71 kB - libuuid-devel-2.17.2-12.4.AXS4.i686.rpm
MD5: 2f6178323c04e8e741cb8acaa280619b
SHA-256: 62c6b43d270276c3bae225eec353fc79aa8958e1411a0abda201dc63101de32c
Size: 80.32 kB - util-linux-ng-2.17.2-12.4.AXS4.i686.rpm
MD5: f0568a44cea8e754024ea2add59515d5
SHA-256: 359ceee0ca8d90c09aaa0f705b467865684dc034b5e13ca497cca6cd41f3a6bf
Size: 1.51 MB