[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Translated]security/2000/20001119



ä¹…ä¿ç”°ã§ã™ã€‚

At Thu, 8 Nov 2001 21:09:37 +0900,
NOGAMI Daisuke wrote:

> 野上ã§ã™ã€‚
> 予約ã—ã¦ã‹ã‚‰ã ã„ã¶ãŸã¡ã¾ã—ãŸãŒã€ã‚»ã‚­ãƒ¥ãƒªãƒ†ã‚£ã®æ®‹ã‚Šã®è¨³ã€ãã®ï¼”ã§ã™ã€‚

cvs.debian.org ã« cvs commit ã—ã¾ã—ãŸã€‚

 * 「プリンターã€ã€Œãƒ¦ãƒ¼ã‚¶ãƒ¼ã€â†’「プリンタã€ã€Œãƒ¦ãƒ¼ã‚¶ã€ã¨çµ±ä¸€ã—ã¾ã—ãŸã€‚

 * <p>2ã¤ç›®ã®å•é¡Œã¯ CUPS ã®è¨­å®šã«ã‚ˆã‚‹ã‚‚ã®ã§ã™ã€‚ CUPS 㯠Apache ã«è¿‘ã„å½¢ã§ã‚¢ã‚¯ã‚»ã‚¹åˆ¶å¾¡ã‚’è¡Œã„ã€è¨­å®šã‚‚åˆæœŸçŠ¶æ…‹ã§ã¯ Apache ã®æ–¹æ³•ã«è¿‘ã„ã‚‚ã®ã§ã™ã€‚ã“ã‚Œã¯ã€ãƒ—リンタã«ç›´æŽ¥ãµã‚Œã‚‹ã“ã¨ãŒå‡ºæ¥ã‚‹äººã€…ã«æã‚ã—ã„ç§ç‰©åŒ–を許ã™ã‚‚ã®ã§ã¯ã‚ã‚Šã¾ã›ã‚“。ã¾ãŸã€ç®¡ç†è€…ã®ã‚¿ã‚¹ã‚¯ã‚‚許ã•ã‚Œã¾ã›ã‚“。ã—ã‹ã—ã€ã‚¤ãƒ³ã‚¿ãƒ¼ãƒãƒƒãƒˆã®ãƒ¦ãƒ¼ã‚¶ãƒ¼ã¯(ãŸã¨ãˆã°)ã‚ãªãŸã®ãƒ—リンタã®ç´™ã‚’ã™ã¹ã¦å‡ºã—ã¦ã—ã¾ã†ã“ã¨ãŒå‡ºæ¥ã¾ã™ã€‚ Debian ã¯ã€ potato ã‚„ woody ã«ãŠã„ã¦ã€ã“ã®å¾Œè€…ã®å•é¡Œã«å¯¾ã™ã‚‹è„†å¼±æ€§ã‚’æŒã£ãŸçŠ¶æ…‹ã§å‡ºè·ã•ã‚Œã¦ã„ã¾ã™ã€‚

   ã®éƒ¨åˆ†ãŒã€ã‚ˆãã‚ã‹ã‚‰ãªã„ã®ã§ã™ãŒã€ä»¥ä¸‹ã®ã‚ˆã†ãªæ„味ã ã¨æ€ã„ã¾ã™ã€‚

 * <p>2ã¤ç›®ã®å•é¡Œã¯ CUPS ã®è¨­å®šã«ã‚ˆã‚‹ã‚‚ã®ã§ã™ã€‚CUPS 㯠Apache ã«è¿‘ã„
   å½¢ã§ã‚¢ã‚¯ã‚»ã‚¹åˆ¶å¾¡ã‚’è¡Œã„ã€è¨­å®šã‚‚åˆæœŸçŠ¶æ…‹ã§ã¯ Apache ã®æ–¹æ³•ã«è¿‘ã„ã‚‚ã®
   ã§ã™ã€‚ã“ã‚Œã¯ã€äººã€…ã«ãƒ—リンタをæ“作ã™ã‚‹ã“ã¨ã‚’許å¯ã™ã‚‹å ´åˆã«ã¯ã€éžå¸¸
   ã«é©åˆ‡ã§ã‚ã‚‹ã¨ã¯è¨€ãˆã¾ã›ã‚“。インターãƒãƒƒãƒˆä¸Šã®ãƒ¦ãƒ¼ã‚¶ã¯ã€ãƒ—リンタã®
   管ç†ã‚¿ã‚¹ã‚¯ã‚’è¡Œã†ã“ã¨ã¯ä¾ç„¶ã¨ã—ã¦ã§ãã¾ã›ã‚“ãŒã€(ãŸã¨ãˆã°) ã‚ãªãŸã®
   プリンタã®ç´™ã‚’ã™ã¹ã¦å‡ºã—ã¦ã—ã¾ã†ã“ã¨ãŒã§ãã¾ã™ã€‚Debian ã¯ã€potato
   ã‚„ woody ã«ãŠã„ã¦ã€ã“ã®å¾Œè€…ã®å•é¡Œã«å¯¾ã™ã‚‹è„†å¼±æ€§ã‚’æŒã£ãŸçŠ¶æ…‹ã§å‡ºè·
   ã•ã‚Œã¦ã„ã¾ã™ã€‚

   ã©ã†ã§ã—ょã†ã‹... 原文ã¯ã€

<p>The second problem has to do with CUPS's configuration. CUPS does access
control in a similar way to Apache, and is configured by default in a similar
way to Apache. This isn't terribly appropriate in the case of allowing people
to attach to printers. Administrative tasks still aren't allowed, but Internet
users could (for example) run all the paper out of your printer. Debian as
shipped in potato and woody is vulnurable to this latter problem.  

   ã§ã™ã€‚

---
ä¹…ä¿ç”°æ™ºåºƒ Tomohiro KUBOTA <kubota@debian.org>
http://www.debian.or.jp/~kubota/
"Introduction to I18N"  http://www.debian.org/doc/manuals/intro-i18n/