[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

security/2003/dsa-39[0-4].wml



いまいです。

だいぶ時間が経ちましたが、残りの security/2003/dsa-39[0-4].wml を終わ
らせました。チェックをお願いします。

ついでに、dsa-38x を予約します。
--
Nobuhiro IMAI <nov@xxxxxxxxxxxx>
Key fingerprint = F39E D552 545D 7C64 D690  F644 5A15 746C BD8E 7106
#use wml::debian::translation-check translation="1.1"
<define-tag description>$B%P%C%U%!%*!<%P%U%m!<(B</define-tag>
<define-tag moreinfo>
<p>Steve Kemp $B$5$s$K$h$j!"(Bmarbles $B$,4D6-JQ?t(B HOME
$B$r=hM}$9$k:]$N%P%C%U%!%*!<%P%U%m!<$,H/8+$5$l$^$7$?!#$3$N@H<e@-$K$h$j!"(B
$B%m!<%+%k%f!<%6$,%0%k!<%W(B games $B$N8"8B$r<hF@$G$-$F$7$^$$$^$9!#(B</p>

<p>$B0BDjHG%G%#%9%H%j%S%e!<%7%g%s(B (woody) $B$G$O!"(B
$B$3$NLdBj$O%P!<%8%g%s(B 1.0.2-1woody1 $B$G=$@5$5$l$F$$$^$9!#(B</p>

<p>$BIT0BDjHG%G%#%9%H%j%S%e!<%7%g%s(B (sid) $B$G$O!"(B
$B$3$NLdBj$O4V$b$J$/=$@5$5$l$kM=Dj$G$9!#(B</p>

<p>$BD>$A$K(B marbles $B%Q%C%1!<%8$r%"%C%W%0%l!<%I$9$k$3$H$r$*4+$a$7$^$9!#(B</p>
</define-tag>

# do not modify the following line
#include "$(ENGLISHDIR)/security/2003/dsa-390.data"
#use wml::debian::translation-check translation="1.1"
<define-tag description>$B%P%C%U%!%*!<%P%U%m!<(B</define-tag>
<define-tag moreinfo>
<p>Steve Kemp $B$5$s$K$h$j!"(Bfreesweep $B$,$$$/$D$+$N4D6-JQ?t$r=hM}$9$k:]$N(B
$B%P%C%U%!%*!<%P%U%m!<$,H/8+$5$l$^$7$?!#$3$N@H<e@-$K$h$j!"(B
$B%m!<%+%k%f!<%6$,%0%k!<%W(B games $B$N8"8B$r<hF@$G$-$F$7$^$$$^$9!#(B</p>

<p>$B0BDjHG%G%#%9%H%j%S%e!<%7%g%s(B (woody) $B$G$O!"(B
$B$3$NLdBj$O%P!<%8%g%s(B 0.88-4woody1 $B$G=$@5$5$l$F$$$^$9!#(B</p>

<p>$BIT0BDjHG%G%#%9%H%j%S%e!<%7%g%s(B (sid) $B$G$O!"(B
$B$3$NLdBj$O4V$b$J$/=$@5$5$l$kM=Dj$G$9!#(B</p>

<p>$BD>$A$K(B freesweep $B%Q%C%1!<%8$r%"%C%W%0%l!<%I$9$k$3$H$r$*4+$a$7$^$9!#(B</p>
</define-tag>

# do not modify the following line
#include "$(ENGLISHDIR)/security/2003/dsa-391.data"
#use wml::debian::translation-check translation="1.2"
<define-tag description>$B%P%C%U%!%*!<%P%U%m!<!"%U%!%$%k!&%G%#%l%/%H%j$NK=O*(B</define-tag>
<define-tag moreinfo>
<p>Jens Steube $B$5$s$K$h$j!"@EE*%3%s%F%s%D$r07$&7ZNL(B HTTP $B%5!<%P$N(B webfs
$B$KFs$D$N@H<e@-$,Js9p$5$l$^$7$?!#(B</p>

<p> <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0832";>CAN-2003-0832</a> - $B%P!<%A%c%k%[%9%F%#%s%0$rM-8z$K$7$F$$$k:]$K!"(B
 $B%j%b!<%H$N%/%i%$%"%s%H$O%[%9%HL>$H$7$F(B ".."
 $B$r%j%/%(%9%H$K4^$a$k$3$H$,$G$-$^$9!#$3$l$K$h$j!"(B
 $B%I%-%e%a%s%H%k!<%H$h$j>e$N3,AX$N%G%#%l%/%H%j0lMw$d!"(B
 $B%U%!%$%k$N<hF@$,$G$-$F$7$^$$$^$9!#(B</p>

<p> <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0833";>CAN-2003-0833</a> - $BD9$$%Q%9L>$r;H$&$H!"%9%?%C%/>e$K<h$i$l$?%P%C%U%!$,%*!<%P%U%m!<$7!"(B
 $BG$0U$N%3!<%I$N<B9T$r5v$7$F$7$^$$$^$9!#$3$N@H<e@-$r967b$9$k$K$O!"(B
 $B%5!<%P>e$K%&%'%V%5!<%P$+$i%"%/%;%92DG=$J%G%#%l%/%H%j$r:n@.$9$kI,MW$,$"$j$^$9!#(B<a
 href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0832";>CAN-2003-0832</a>
 $B$HAH$_9g$o$;$k$H!"$3$l$O(B <code>/var/tmp</code>
 $B$N$h$&$KC/$G$b=q$-9~$a$k%G%#%l%/%H%j$r;H$C$F967b2DG=$H$J$j$^$9!#(B</p>

<p>$B0BDjHG%G%#%9%H%j%S%e!<%7%g%s(B (woody) $B$G$O!"(B
$B$3$l$i$NLdBj$O%P!<%8%g%s(B 1.17.2 $B$G=$@5$5$l$F$$$^$9!#(B</p>

<p>$BIT0BDjHG%G%#%9%H%j%S%e!<%7%g%s(B (sid) $B$G$O!"(B
$B$3$l$iLdBj$O%P!<%8%g%s(B 1.20 $B$G=$@5$5$l$F$$$^$9!#(B</p>

<p>$BD>$A$K(B webfs $B%Q%C%1!<%8$r%"%C%W%0%l!<%I$9$k$3$H$r$*4+$a$7$^$9!#(B</p>
</define-tag>

# do not modify the following line
#include "$(ENGLISHDIR)/security/2003/dsa-392.data"
#use wml::debian::translation-check translation="1.2"
<define-tag description>$B%5!<%S%9ITG=(B (DoS) $B967b(B</define-tag>
<define-tag moreinfo>
<p>Dr. Stephen Henson (<email "steve@xxxxxxxxxxx">) $B$5$s$O(B NISCC
(<url "http://www.niscc.gov.uk/";>) $B$N:n@.$7$?%F%9%H%W%m%0%i%`$r;H$C$F!"(B
OpenSSL $B$N(B ASN1 $B%3!<%I$KJ#?t$N8m$j$rH/8+$7$^$7$?!#$3$N8m$j$rAH$_9g$o$;$k$H!"(B
$BI,MW$J$$>l9g$G$b(B OpenSSL $B$K%/%i%$%"%s%H>ZL@=q$N2r@O$r9T$o$;$k$3$H$,$G$-!"(B
$B%3!<%I$N;H$$J}$K<!Bh$G(B OpenSSL $B$N%3!<%I$r;H$&%7%9%F%`$r%5!<%S%9ITG=(B (DoS)
$B>uBV$K$9$k$3$H$,$G$-$^$9!#Nc$($P(B apache-ssl $B$d(B ssh $B$O(B OpenSSH
$B$N%i%$%V%i%j$K%j%s%/$7$F$$$^$9$,!"$3$N@H<e@-$K$O1F6A$5$l$^$;$s!#$7$+$7!"(B
$BB>$N(B OpenSSL $BBP1~$N%"%W%j%1!<%7%g%s$K$O@H<e@-$,$"$k$+$b$7$l$J$$$N$G!"(BOpenSSL
$B$N%"%C%W%0%l!<%I$r$*4+$a$7$^$9!#(B</p>

<p>$B0BDjHG%G%#%9%H%j%S%e!<%7%g%s(B (woody) $B$G$O!"(B
$B$3$NLdBj$O%P!<%8%g%s(B 0.9.6c-2.woody.4 $B$G=$@5$5$l$F$$$^$9!#(B</p>

<p>$BIT0BDjHG%G%#%9%H%j%S%e!<%7%g%s(B (sid) $B$G$O!"(B
$B$3$NLdBj$O%P!<%8%g%s(B 0.9.7c-1 $B$G=$@5$5$l$F$$$^$9!#(B</p>

<p>$BD>$A$K(B openssl $B%Q%C%1!<%8$r%"%C%W%0%l!<%I$9$k$3$H$r$*4+$a$7$^$9!#(B
$B$^$?!"%"%C%W%0%l!<%I$rM-8z$K$9$k$?$a$K$O!"(Blibssl
$B%i%$%V%i%j$r;H$C$F$$$k%5!<%S%9$r:F5/F0$9$kI,MW$,$"$k$N$GCm0U$7$F$/$@$5$$!#(B</p>
</define-tag>

# do not modify the following line
#include "$(ENGLISHDIR)/security/2003/dsa-393.data"
#use wml::debian::translation-check translation="1.2"
<define-tag description>ASN.1 $B2r@O$N@H<e@-(B</define-tag>
<define-tag moreinfo>
<p>OpenSSL $B%3%"%A!<%`$N(B Steve Henson $B$5$s$O!"(BBritish National
Infrastructure Security Coordination Centre (NISCC)
$B$N%F%9%H%W%m%0%i%`$K$h$jH/8+$5$l$?!"(BOpenSSL $B$N(B ASN1
$B%3!<%I$K$"$kJ#?t$N@H<e@-$rFCDj$7!"=$@5HG$rMQ0U$7$^$7$?!#(B</p>

<p>OpenSSL $B$,(B SSL/TLS $B%/%i%$%"%s%H$+$i$N%/%i%$%"%s%H>ZL@=q$r!"(B
$B%W%m%H%3%k%(%i!<$H$7$F5qH]$9$Y$->l9g$K$b2r@O$7$F$7$^$&$H$$$&!"(BOpenSSL
$B$N(B SSL/TLS $B%W%m%H%3%k4XO"$N%P%0$bH/8+$5$l$^$7$?!#(B</p>

<p>The Common Vulnerabilities and Exposures $B%W%m%8%'%/%H$G$O!"(B
$B0J2<$NLdBj$rG'<1$7$F$$$^$9!#(B</p>

<ul>

<li><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0543";>CAN-2003-0543</a>:

<p>OpenSSL $B$N@0?t%*!<%P%U%m!<$K$h$j!"%j%b!<%H$N967b<T$,$"$k<o$N(B ASN.1
   $B%?%0CM$r;}$C$?(B SSL $B%/%i%$%"%s%H>ZL@=q$rMQ$$$F!"%5!<%S%9ITG=967b(B ($B%/%i%C%7%e(B)
   $B$r0z$-5/$3$9$3$H$,$G$-$^$9!#(B</p>

<li><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0544";>CAN-2003-0544</a>:

<p>OpenSSL $B$O$"$k<o$N(B ASN.1 $BF~NO$NJ8;z?t$r@5$7$/C5CN$G$-$^$;$s!#(B
   $B$3$l$K$h$j%j%b!<%H$N967b<T$+$i!"%m%s%0%U%)!<%`$,;H$o$l$F$$$k:]$K(B
   $B%P%C%U%!$N=*C<$r1[$($FFI$_=P$9$h$&$K:Y9)$5$l$?(B SSL $B%/%i%$%"%s%H>ZL@=q$rMQ$$$F!"(B
   $B%5!<%S%9ITG=967b(B ($B%/%i%C%7%e(B) $B$r0z$-5/$3$9$3$H$,$G$-$^$9!#(B</p>

<li><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0545";>CAN-2003-0545</a>:

<p>$BIT@5$J(B ASN.1 $B%(%s%3!<%G%#%s%0$r;}$C$?$"$k<o$N(B SSL
   $B%/%i%$%"%s%H>ZL@=q$rMQ$$$F%a%b%j$NFs=E3+J|$r0z$-5/$3$7!"(B
   $B%j%b!<%H$N967b<T$+$i%5!<%S%9ITG=967b(B ($B%/%i%C%7%e(B) $B$d!"(B
   $B>l9g$K$h$C$F$OG$0U$N%3!<%I$N<B9T$r5v$7$F$7$^$$$^$9!#(B
   $B$3$N%P%0$O(B OpenSSL 0.9.7 $B$N$_$KB8:_$7!"$3$3$G$O;2>H$H$7$F$N$_7G:\$7$F$$$^$9!#(B
   </p>

</ul>

<p>$B0BDjHG%G%#%9%H%j%S%e!<%7%g%s(B (woody) $B$G$O!"(B
$B$3$NLdBj$O(B openssl095 $B%P!<%8%g%s(B 0.9.5a-6.woody.3 $B$G=$@5$5$l$F$$$^$9!#(B</p>

<p>$B$3$N%Q%C%1!<%8$O!"IT0BDjHG(B (unstable$B!"(Bsid) $B$d%F%9%HHG(B (testing$B!"(Bsarge)
$B$K$OB8:_$7$^$;$s!#(B</p>

<p>$BD>$A$K(B libssl095a $B%Q%C%1!<%8$r%"%C%W%0%l!<%I$7!"(B
$B$3$N%i%$%V%i%j$r;H$C$F$$$k%5!<%S%9$r:F5/F0$9$k$3$H$r$*4+$a$7$^$9!#(BDebian
$B$K$O$3$N%i%$%V%i%j$K%j%s%/$7$?%Q%C%1!<%8$O$"$j$^$;$s!#(B</p>

<p>(Ray Dassen $B$5$s$h$jDs6!$7$FD:$$$?(B) $B0J2<$N%3%^%s%I%i%$%s$O!"(B
$B%a%b%j6u4VFb$K(B libssl095 $B$,%^%C%W$5$l$F$$$k<B9TCf$N%W%m%;%9L>$N%j%9%H$r:n@.$7$^$9!#(B
</p>

<pre>
    find /proc -name maps -exec egrep -l 'libssl095' {} /dev/null \; \
    | sed -e 's/[^0-9]//g' | xargs --no-run-if-empty ps --no-headers -p | \
    sed -e 's/^\+//' -e 's/ \+/ /g' | cut -d ' ' -f 5 | sort | uniq
</pre>

<p>$B4XO"$9$k%5!<%S%9$r:F5/F0$7$F$/$@$5$$!#(B</p>
</define-tag>

# do not modify the following line
#include "$(ENGLISHDIR)/security/2003/dsa-394.data"