openssh-5.3p1-84.1.AXS4
エラータID: AXSA:2013-105:01
リリース日:
2013/03/04 Monday - 13:00
題名:
openssh-5.3p1-84.1.AXS4
影響のあるチャネル:
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- pam_ssh_agent_auth モジュールのビルドで OpenSSH コードベースの error 関数の代わりに glibc error 関数を呼び出してしまい,このモジュールを信頼する巧妙に細工されたアプリケーションの使用で,プロセスメモリからローカルのユーザが機密情報を得たり,権限を得る可能性のある脆弱性があります。(CVE-2012-5536)
一部CVEの翻訳文はJVNからの引用になります。
http://jvndb.jvn.jp/
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2012-5536
A certain Red Hat build of the pam_ssh_agent_auth module on Red Hat Enterprise Linux (RHEL) 6 and Fedora Rawhide calls the glibc error function instead of the error function in the OpenSSH codebase, which allows local users to obtain sensitive information from process memory or possibly gain privileges via crafted use of an application that relies on this module, as demonstrated by su and sudo.
A certain Red Hat build of the pam_ssh_agent_auth module on Red Hat Enterprise Linux (RHEL) 6 and Fedora Rawhide calls the glibc error function instead of the error function in the OpenSSH codebase, which allows local users to obtain sensitive information from process memory or possibly gain privileges via crafted use of an application that relies on this module, as demonstrated by su and sudo.
追加情報:
N/A
ダウンロード:
SRPMS
- openssh-5.3p1-84.1.AXS4.src.rpm
MD5: 8da8d86c2498c778e0a3c2f4b96e67f4
SHA-256: 1af9b53caedd4ca1bbc331c99b1c425378c49e9ed18f5f4c50abf9f90911933e
Size: 1.25 MB
Asianux Server 4 for x86
- openssh-5.3p1-84.1.AXS4.i686.rpm
MD5: 3a1d92abe8f1ab7bcf933b3616dcbc9d
SHA-256: daa84d0a82807db3bcd88cb41926e0df2d877c1029b1d915c05f940d0749f760
Size: 236.93 kB - openssh-askpass-5.3p1-84.1.AXS4.i686.rpm
MD5: 2a1cd89124b375769b8acc0e13a42dbd
SHA-256: a748d3e7f9144e4aee87ab8b017aa052f1a652e95335be54255f4a84bf158f46
Size: 51.92 kB - openssh-clients-5.3p1-84.1.AXS4.i686.rpm
MD5: 944ad2564f24dd50392988214e0db437
SHA-256: 54feaaaa93e29a108cffd9395f831d0712ffac6e28c9cc8b87b2e5b6df582cb6
Size: 360.00 kB - openssh-server-5.3p1-84.1.AXS4.i686.rpm
MD5: f4bb20ba797c2d8bb8dbd12e0971b773
SHA-256: b56acf38584e4199a24e7422e02bd2cd170b34a9a01420ff633d8692eb0b84c6
Size: 297.11 kB
Asianux Server 4 for x86_64
- openssh-5.3p1-84.1.AXS4.x86_64.rpm
MD5: 4e1c862ff1e6f601a594153b924ea396
SHA-256: 5b93d97bb662b2eda95d37a2840efb91395cdc9e263353cb619cdcb8132b562d
Size: 234.92 kB - openssh-askpass-5.3p1-84.1.AXS4.x86_64.rpm
MD5: d149bc99cf50758040550242927cb0be
SHA-256: 0847615844786342c1b1f25e739e1dec46bfa83225abde77736e1a3c11adc725
Size: 51.63 kB - openssh-clients-5.3p1-84.1.AXS4.x86_64.rpm
MD5: 520011b4558b3a2a6780b4fe2cfb198a
SHA-256: 8e4d08fbf96324b77fbe04a65b5f9883b1e000325d7be2889c308c73a9068168
Size: 354.07 kB - openssh-server-5.3p1-84.1.AXS4.x86_64.rpm
MD5: f03622c5d9e2f9a19101e063afbc1e31
SHA-256: 03da176fdebe8567f122d6b815a663c7c729a605f5086db88683018464d25c2d
Size: 298.05 kB