openssh-5.3p1-123.AXS4

エラータID: AXSA:2017-2173:02

リリース日: 
2017/09/12 Tuesday - 17:59
題名: 
openssh-5.3p1-123.AXS4
影響のあるチャネル: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

OpenSSH is an SSH protocol implementation supported by a number of Linux,
UNIX, and similar operating systems. It includes the core files necessary for
both the OpenSSH client and server.

Security Fix(es):

* A covert timing channel flaw was found in the way OpenSSH handled
authentication of non-existent users. A remote unauthenticated attacker could
possibly use this flaw to determine valid user names by measuring the timing of
server responses. (CVE-2016-6210)

CVE-2016-6210
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user
password hashing, uses BLOWFISH hashing on a static password when the
username does not exist, which allows remote attackers to enumerate
users by leveraging the timing difference between responses when a
large password is provided.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. openssh-5.3p1-123.AXS4.src.rpm
    MD5: 0e3233ae666c0e8b929e6d6e3fab00f1
    SHA-256: 680d9ebd6638232a90c32233d53d8e3db6066981b4828056820fee1b409e2337
    Size: 1.47 MB

Asianux Server 4 for x86
  1. openssh-5.3p1-123.AXS4.i686.rpm
    MD5: e6a38d3d74c6e5e22a1adf92ef3b784d
    SHA-256: e177603e7f7ef4d8cdcaf2ee9ddf44a651c336fd30158bf610a057d40b5bfe35
    Size: 279.03 kB
  2. openssh-askpass-5.3p1-123.AXS4.i686.rpm
    MD5: 9536465befcf7f3373861458c6e3d214
    SHA-256: 637816d8273259585bb9d275269d47ae332d4bdaec29f07c94cc2ab299b20d4c
    Size: 60.53 kB
  3. openssh-clients-5.3p1-123.AXS4.i686.rpm
    MD5: e05fecdc88f9fa0bdcf706457c07e0c9
    SHA-256: d8d5b8de9f5031ce04ed61a47244258a568afec4c4d1249186fa0b02fb325102
    Size: 449.69 kB
  4. openssh-server-5.3p1-123.AXS4.i686.rpm
    MD5: ac9b16c4cb25e97cb5a86ca6f9a2780e
    SHA-256: 5a86de6dc6ed8570f6144c765b9985f3808fd7bb94f1ac1795f24fe991b92072
    Size: 327.48 kB

Asianux Server 4 for x86_64
  1. openssh-5.3p1-123.AXS4.x86_64.rpm
    MD5: 4fc6fcbbb0eddf38d6bd205d9fd40a0b
    SHA-256: fc12b8c9a85a03fba64b43040e147c057244b7cc97dc338e1475c668ba0caf29
    Size: 276.54 kB
  2. openssh-askpass-5.3p1-123.AXS4.x86_64.rpm
    MD5: 74ccfa5007fb4ac419eaad4b5b52ed10
    SHA-256: 393d8464f5c1415898f4472f5db4d56bf204db5cbca47c4b2e33cb6b423f96ae
    Size: 60.26 kB
  3. openssh-clients-5.3p1-123.AXS4.x86_64.rpm
    MD5: 47eedf749cb93608cc863f0cf84ab0d9
    SHA-256: 9f549a8ccbdd40b53b3ca07bfcb532f92a2899bc54c65012a72cdbf81544be29
    Size: 442.65 kB
  4. openssh-server-5.3p1-123.AXS4.x86_64.rpm
    MD5: b3aa28a651063909e4021c11883d1331
    SHA-256: 60581a097e371ca1abdaf3e0a4c57b165ae5b59b2bc8f1152d48ba7e113166f3
    Size: 328.34 kB