openssh-5.3p1-94.AXS4
エラータID: AXSA:2014-030:01
リリース日:
2014/03/18 Tuesday - 19:30
題名:
openssh-5.3p1-94.AXS4
影響のあるチャネル:
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- OpenSSH のデフォルトの設定は TCP コネクション確立とログインの完了の間の固定の時間制限を強制しており,一時的に多くの新しい TCP コネクションを作成することで,リモートの攻撃者がサービス拒否 (コネクションスロットの枯渇) を引き起こす脆弱性があります。(CVE-2010-5107)
一部CVEの翻訳文はJVNからの引用になります。
http://jvndb.jvn.jp/
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2010-5107
The default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login, which makes it easier for remote attackers to cause a denial of service (connection-slot exhaustion) by periodically making many new TCP connections.
The default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login, which makes it easier for remote attackers to cause a denial of service (connection-slot exhaustion) by periodically making many new TCP connections.
追加情報:
N/A
ダウンロード:
SRPMS
- openssh-5.3p1-94.AXS4.src.rpm
MD5: e6d7a7a92bf1f7399280ff7a532c3647
SHA-256: 883dbece21b944ba597b480c4303a9858e9137a55381ea9f467e4bacc8f6aabc
Size: 1.35 MB
Asianux Server 4 for x86
- openssh-5.3p1-94.AXS4.i686.rpm
MD5: 4e40e59bae0a7e81080e0cb38329da3b
SHA-256: 3ef1a0a3fe1829aef2e3ac431e6c18631c7ee3419f4cbfcb5b08c207ea1c66e2
Size: 259.93 kB - openssh-askpass-5.3p1-94.AXS4.i686.rpm
MD5: a7f921d44687eeeb238e88972e5f5779
SHA-256: 3bd3da0f5fc2ddad9ce4df4f969155d664c5f42510444608cce3dd739f62178b
Size: 53.74 kB - openssh-clients-5.3p1-94.AXS4.i686.rpm
MD5: ec909423e51b5703ed85590247721ee5
SHA-256: f359716d361f9e2c727cf0dfccdc2e312040ae96380bcb042c6cf3d65cc38b30
Size: 397.38 kB - openssh-server-5.3p1-94.AXS4.i686.rpm
MD5: cedbc983ca7b8e9cf8278d4e02f44502
SHA-256: 4d195de293afcdd4b7b84621cb53d75111613795a2a2ac2adf9432a18d347a37
Size: 309.72 kB
Asianux Server 4 for x86_64
- openssh-5.3p1-94.AXS4.x86_64.rpm
MD5: 2b0af77371cf9a02ea917051dc5e81eb
SHA-256: 50f09a30f980c5c08086061576dcde1d6b998ea1bd3da9ccccc447d4fa0a1aba
Size: 257.67 kB - openssh-askpass-5.3p1-94.AXS4.x86_64.rpm
MD5: fd38e831a845b2986603063fba96867c
SHA-256: 47359f1831016c4a8328dad00a12669188263c4013d331378acfb31248a2af5a
Size: 53.45 kB - openssh-clients-5.3p1-94.AXS4.x86_64.rpm
MD5: a8d12de5188bfd3dcbd076cc8db16939
SHA-256: e9c483da2bd2951ae525ea08a473f840373400728a6ac0599d634813e5eb818f
Size: 401.46 kB - openssh-server-5.3p1-94.AXS4.x86_64.rpm
MD5: 217c9cb903bf5138934f77e048f23714
SHA-256: 5ba3038eabeef1b9d1301dd2e62c837c874310a9f4a6e2129c841fbd76dce431
Size: 311.68 kB