[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: security/2006/dsa-1146.wml
æ‰å±±ã§ã™ã€‚
From: NAKANO Takeo <nakano@xxxxxxxxxxxxxxx>
Date: Thu, 10 Aug 2006 17:51:46 +0900
In "debian-www : 09871"
> ä¸é‡Žã§ã™ã€‚
>  Debian-users ã¸ã‚‚訳をæµã—ã¾ã—ãŸãŒã€
> In certain application programs packaged in the MIT Kerberos 5 source
> distribution, calls to setuid() and seteuid() are not always checked
> for success and which may fail with some PAM configurations.
> ã®å¾ŒåŠã¯ã€ã€Œç‰¹å®šã® PAM ã®è¨å®šã«ã‚ˆã£ã¦ã¯ setuid() ã‚„ seteiud() ga
> 失敗ã™ã‚‹å¯èƒ½æ€§ãŒã‚ã‚‹ã‘ã©ã€kerberos ã®ãƒ—ãƒã‚°ãƒ©ãƒ ã§ã“れらã®å‘¼å‡ºã—ã®
> æˆåŠŸãƒã‚§ãƒƒã‚¯ã‚’è¡Œã£ã¦ã„ãªã„ã€ã ã¨æ€ã„ã¾ã™ã€‚
ã©ã†ã‚‚ã‚ã‚ŠãŒã¨ã†ã”ã–ã„ã¾ã™ã€‚
and which 以下㮠"may fail with some PAM configurations" ã¯
"calls" ã«ã‹ã‹ã‚‹ã‚“ã§ã™ã。å‰åŠéƒ¨åˆ†ã‚‚ãªã‚“ã‹é–“é•ã£ã¦ã„ãŸã‚ˆã†ãªã®ã§
ã¨ã¦ã‚‚助ã‹ã‚Šã¾ã—ãŸã€‚
------------------------------------------------------------------
#use wml::debian::translation-check translation="1.1"
<define-tag description>プãƒã‚°ãƒ©ãƒ 上ã®èª¤ã‚Š</define-tag>
<define-tag moreinfo>
<p>MIT Kerberos 5
ソースパッケージã«å«ã¾ã‚Œã‚‹ä¸€éƒ¨ã®ã‚¢ãƒ—リケーションプãƒã‚°ãƒ©ãƒ ã«ãŠã„ã¦ã€setuid()
ã‚„ seteuid() ã¸ã®å‘¼ã³å‡ºã—ãŒæˆåŠŸã—ãŸã‹ã©ã†ã‹ã®ãƒã‚§ãƒƒã‚¯ãŒã€
(PAM ã®è¨å®šã«ã‚ˆã£ã¦ã¯å¤±æ•—ã™ã‚‹å¯èƒ½æ€§ãŒã‚ã‚‹ã«ã‚‚ã‹ã‹ã‚らãš)
完全ã«ã¯è¡Œã‚ã‚Œã¦ã„ã¾ã›ã‚“。ãƒãƒ¼ã‚«ãƒ«ã®ãƒ¦ãƒ¼ã‚¶ãŒã“れらã®è„†å¼±æ€§ã‚’悪用ã™ã‚‹ã“ã¨ã§ã€
権é™ã®æ˜‡æ ¼ãŒå¯èƒ½ã§ã™ã€‚ç¾æ™‚点ã§ã¯ã„ã‹ãªã‚‹æ”»æ’ƒã‚³ãƒ¼ãƒ‰ã‚‚å˜åœ¨ã—ã¾ã›ã‚“。</p>
<p>安定版ディストリビューション (stableã€ã‚³ãƒ¼ãƒ‰ãƒãƒ¼ãƒ sarge)
ã§ã¯ã€ã“れらã®å•é¡Œã¯ãƒãƒ¼ã‚¸ãƒ§ãƒ³ 1.3.6-2sarge3 ã§ä¿®æ£ã•ã‚Œã¦ã„ã¾ã™ã€‚</p>
<p>ä¸å®‰å®šç‰ˆãƒ‡ã‚£ã‚¹ãƒˆãƒªãƒ“ューション (unstableã€ã‚³ãƒ¼ãƒ‰ãƒãƒ¼ãƒ sid)
ã§ã¯ã€ã“れらã®å•é¡Œã¯ãƒãƒ¼ã‚¸ãƒ§ãƒ³ 1.4.3-9 ã§ä¿®æ£ã•ã‚Œã¦ã„ã¾ã™ã€‚</p>
<p>krb5 パッケージã®ã‚¢ãƒƒãƒ—グレードをãŠå‹§ã‚ã—ã¾ã™ã€‚</p>
</define-tag>
# do not modify the following line
#include "$(ENGLISHDIR)/security/2006/dsa-1146.data"