openssh-5.3p1-81.AXS4
エラータID: AXSA:2012-593:02
リリース日:
2012/07/25 Wednesday - 10:00
題名:
openssh-5.3p1-81.AXS4
影響のあるチャネル:
Asianux Server 4 for x86
Asianux Server 4 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- OpenSSH の gss-serv.c 内の ssh_gssapi_parse_ename 関数には、gssapi-with-mic 認証が有効な場合、サービス運用妨害 (メモリ消費) 状態となる脆弱性が存在します。(CVE-2011-5000)
一部CVEの翻訳文はJVNからの引用になります。
http://jvndb.jvn.jp/
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2011-5000
The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote authenticated users to cause a denial of service (memory consumption) via a large value in a certain length field. NOTE: there may be limited scenarios in which this issue is relevant.
The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote authenticated users to cause a denial of service (memory consumption) via a large value in a certain length field. NOTE: there may be limited scenarios in which this issue is relevant.
追加情報:
N/A
ダウンロード:
SRPMS
- openssh-5.3p1-81.AXS4.src.rpm
MD5: bd61bda477ea8fc69d63ff6fbef917ec
SHA-256: 1381203847930ee4c8c74d1d07949cbd1dcf5efa66425dff9eceaf5b3acdd712
Size: 1.26 MB
Asianux Server 4 for x86
- openssh-5.3p1-81.AXS4.i686.rpm
MD5: 8fbc3fed485bded46126ff6b68e6ccd2
SHA-256: 799978d4fb735b106c2f5d921073ea99f122711f52f12be68b919b40798e8819
Size: 237.10 kB - openssh-askpass-5.3p1-81.AXS4.i686.rpm
MD5: b335e2944349b407f9c510872f17dbb9
SHA-256: d14425517f5a5491d395b9c7e9d979e1120b07de9c15e6b07856f0de439a0d68
Size: 51.34 kB - openssh-clients-5.3p1-81.AXS4.i686.rpm
MD5: 96cd72c947321330a5095c85112e8ca1
SHA-256: ce9d79c671a7c2c657622d786dc1f050db3daa93906ee464af2e266812817c9d
Size: 363.47 kB - openssh-server-5.3p1-81.AXS4.i686.rpm
MD5: 5ce8e5699da54fe66d350ad729b3d60f
SHA-256: cb655fe3feb545c3a0a9cc6c5e2b5d00735b49f97a37460efabcc65804df6ffa
Size: 299.39 kB
Asianux Server 4 for x86_64
- openssh-5.3p1-81.AXS4.x86_64.rpm
MD5: 96a99cd93c684ba006ae7fe2d5d656f9
SHA-256: f2a1993a0e564844458ab1cf1a0845db5e950f38542328fd583531a008a15ede
Size: 235.07 kB - openssh-askpass-5.3p1-81.AXS4.x86_64.rpm
MD5: 87e6f1f41545dd79a4644b597f241517
SHA-256: 282f6094e98d181bf459c593a8f02a8b5c74c7f9a18f3a3cb3200baf3f14cc8f
Size: 51.03 kB - openssh-clients-5.3p1-81.AXS4.x86_64.rpm
MD5: 7fce335a003cfd9aec6c717af0e704ec
SHA-256: 84d35c6a4f89a924620e21d62686593b81eb8fcf526f31cf2e4285f709171fae
Size: 356.89 kB - openssh-server-5.3p1-81.AXS4.x86_64.rpm
MD5: 406bc9eca612e54cad550003a35abeb5
SHA-256: c1f72ea0a414cc7fb2d2596b79700617d177469d45e9d1a5865be73bbebbe559
Size: 299.36 kB