重要(Important):httpdのセキュリティアップデート
| アドバイスID: | RHSA-2005:608-07 |
| 最終更新日: | 2005-09-06 |
| 影響のあるプロダクト: |
Red Hat Desktop (v. 3) Red Hat Desktop (v. 4) Red Hat Enterprise Linux AS (v. 3) Red Hat Enterprise Linux AS (v. 4) Red Hat Enterprise Linux ES (v. 3) Red Hat Enterprise Linux ES (v. 4) Red Hat Enterprise Linux WS (v. 3) Red Hat Enterprise Linux WS (v. 4) |
| CVEs (cve.mitre.org): |
CAN-2005-2700 CAN-2005-2728 |
セキュリティ・アドバイス
概要:
2つのセキュリティ問題を修正したApache httpdのアップデートパッケージが、Red Hat Enterprise Linux 3および4で利用可能になりました。
このアップデートは、レッドハットセキュリティ対策チームによって、深刻度「重要(Important)」のセキュリティ問題と評価されています。
Apache HTTP Serverは広く使用されているWebサーバであり、自由に利用可能です。
mod_sslの「SSLVerifyClient」指示文の処理で欠陥が発見されました。この欠陥は、仮想ホストが「SSLVerifyClient optional」を使用して設定され、指示文「SSLVerifyClient required」が特定のロケーション用に設定されている場合に発生します。サーバがこのように設定されていると、通常は保護する必要のあるリソースに対して、攻撃者が接続時にクライアント証明書を提供することなくアクセスできる可能性があります。「Common Vulnerabilities and Exposures」プロジェクトにより、この問題はCAN-2005-2700と命名されています。
byterangeフィルタによって一部の応答がメモリにバッファされる場合の欠陥がApache httpdで発見されました。サーバが大量のデータを生成するCGIスクリプトやPHPスクリプトのような動的リソースを備えている場合、攻撃者がリソースを消費するために巧妙に作成された要求を送信し、サービス拒否を引き起こす可能性があります(CAN-2005-2728)。
Apache httpdのユーザは、これらの問題を修正するバックポートパッチを含む上記エラータパッケージにアップデートしてください。
アップデート・パッケージ:
| Red Hat Desktop (v. 3) | |
| SRPMS: | |
| httpd-2.0.46-46.3.ent.src.rpm | 484b418c080a8fc60b3add4dfcf1900f |
| IA-32: | |
| httpd-2.0.46-46.3.ent.i386.rpm | 319460633151ee1517c8148931ca72de |
| httpd-devel-2.0.46-46.3.ent.i386.rpm | 6cc3044405158920afedbd288430544c |
| mod_ssl-2.0.46-46.3.ent.i386.rpm | ee51eb393a77fcbc28640ab9c7c0376c |
| x86_64: | |
| httpd-2.0.46-46.3.ent.x86_64.rpm | d1bd5698951993680a3f4d78b332117e |
| httpd-devel-2.0.46-46.3.ent.x86_64.rpm | 9d57852140e597b4719cda1d8aee4101 |
| mod_ssl-2.0.46-46.3.ent.x86_64.rpm | fc4beccd061aa1de3286a4548d820bcc |
| Red Hat Desktop (v. 4) | |
| SRPMS: | |
| httpd-2.0.52-12.2.ent.src.rpm | de6c9583b0be4f8a91d58f9d96082d3c |
| IA-32: | |
| httpd-2.0.52-12.2.ent.i386.rpm | 2b535c428cc468bb8c94e88cb47b48a0 |
| httpd-devel-2.0.52-12.2.ent.i386.rpm | 62933dc89da98cf4e2cdb885cb195d29 |
| httpd-manual-2.0.52-12.2.ent.i386.rpm | 573ee8e079b51dd2d6a474c7513ede63 |
| httpd-suexec-2.0.52-12.2.ent.i386.rpm | ee7ce0885eb313d0f359c89b0d22b637 |
| mod_ssl-2.0.52-12.2.ent.i386.rpm | df4a617088e7c3d22cdb88d149f81209 |
| x86_64: | |
| httpd-2.0.52-12.2.ent.x86_64.rpm | 34ec39c05630e576fad8859e8f233ba7 |
| httpd-devel-2.0.52-12.2.ent.x86_64.rpm | 614164cb0770a14d30eacc211fed4242 |
| httpd-manual-2.0.52-12.2.ent.x86_64.rpm | 2b59b10e2c8e41ed23041e3d433a67c7 |
| httpd-suexec-2.0.52-12.2.ent.x86_64.rpm | 2ce9c581b49e48da9db9b95e61f18ea9 |
| mod_ssl-2.0.52-12.2.ent.x86_64.rpm | 048f5c406bac99d9026eca82573c59f1 |
| Red Hat Enterprise Linux AS (v. 3) | |
| SRPMS: | |
| httpd-2.0.46-46.3.ent.src.rpm | 484b418c080a8fc60b3add4dfcf1900f |
| IA-32: | |
| httpd-2.0.46-46.3.ent.i386.rpm | 319460633151ee1517c8148931ca72de |
| httpd-devel-2.0.46-46.3.ent.i386.rpm | 6cc3044405158920afedbd288430544c |
| mod_ssl-2.0.46-46.3.ent.i386.rpm | ee51eb393a77fcbc28640ab9c7c0376c |
| IA-64: | |
| httpd-2.0.46-46.3.ent.ia64.rpm | 5f9c92619f6a7e60409aeef7b92f5056 |
| httpd-devel-2.0.46-46.3.ent.ia64.rpm | cba1acc27a9904ea4988159c81e96a97 |
| mod_ssl-2.0.46-46.3.ent.ia64.rpm | 15b4dba781df66f9cbcfc0230b96d261 |
| PPC: | |
| httpd-2.0.46-46.3.ent.ppc.rpm | 2ae362a59d4c95ef58879a9f74ec6c30 |
| httpd-devel-2.0.46-46.3.ent.ppc.rpm | 2b61fbe228b61e5d113abd012e9bf619 |
| mod_ssl-2.0.46-46.3.ent.ppc.rpm | 6f653931571bfaebb519aecdbb7150c8 |
| s390: | |
| httpd-2.0.46-46.3.ent.s390.rpm | c59a7c3908fa71b8b7ba36d07cd0d0d4 |
| httpd-devel-2.0.46-46.3.ent.s390.rpm | 2d3f8bf4a5745ba5b87d188f18d04a75 |
| mod_ssl-2.0.46-46.3.ent.s390.rpm | e1bc611d1e4eaecffbc58ff669d16b39 |
| s390x: | |
| httpd-2.0.46-46.3.ent.s390x.rpm | ba883d990a3fc34d2c6d20b6329372c1 |
| httpd-devel-2.0.46-46.3.ent.s390x.rpm | 57c48448f06e2444d285440a6e43631c |
| mod_ssl-2.0.46-46.3.ent.s390x.rpm | 2f44730013c2c1aef58d4c81e9ae613b |
| x86_64: | |
| httpd-2.0.46-46.3.ent.x86_64.rpm | d1bd5698951993680a3f4d78b332117e |
| httpd-devel-2.0.46-46.3.ent.x86_64.rpm | 9d57852140e597b4719cda1d8aee4101 |
| mod_ssl-2.0.46-46.3.ent.x86_64.rpm | fc4beccd061aa1de3286a4548d820bcc |
| Red Hat Enterprise Linux AS (v. 4) | |
| SRPMS: | |
| httpd-2.0.52-12.2.ent.src.rpm | de6c9583b0be4f8a91d58f9d96082d3c |
| IA-32: | |
| httpd-2.0.52-12.2.ent.i386.rpm | 2b535c428cc468bb8c94e88cb47b48a0 |
| httpd-devel-2.0.52-12.2.ent.i386.rpm | 62933dc89da98cf4e2cdb885cb195d29 |
| httpd-manual-2.0.52-12.2.ent.i386.rpm | 573ee8e079b51dd2d6a474c7513ede63 |
| httpd-suexec-2.0.52-12.2.ent.i386.rpm | ee7ce0885eb313d0f359c89b0d22b637 |
| mod_ssl-2.0.52-12.2.ent.i386.rpm | df4a617088e7c3d22cdb88d149f81209 |
| IA-64: | |
| httpd-2.0.52-12.2.ent.ia64.rpm | 2c03808a9cf8081f395259ae21730af0 |
| httpd-devel-2.0.52-12.2.ent.ia64.rpm | 99fcf9f0c7ea2b8a4248cd3a0d25da89 |
| httpd-manual-2.0.52-12.2.ent.ia64.rpm | 856092d56cc712997901f534a76f568c |
| httpd-suexec-2.0.52-12.2.ent.ia64.rpm | 92ac8b5beb4e12b1ead63f7027d07cfb |
| mod_ssl-2.0.52-12.2.ent.ia64.rpm | a44cc800809c368c7455c1af306b8e7d |
| PPC: | |
| httpd-2.0.52-12.2.ent.ppc.rpm | 7f49f8989dd2261c2d137af07e14ff54 |
| httpd-devel-2.0.52-12.2.ent.ppc.rpm | a6e1f360410c36f2cc641e321395fd16 |
| httpd-manual-2.0.52-12.2.ent.ppc.rpm | 69ce88336483a278bcad15ea6eaca096 |
| httpd-suexec-2.0.52-12.2.ent.ppc.rpm | f396126f7386857c22eeeef20d947652 |
| mod_ssl-2.0.52-12.2.ent.ppc.rpm | 99b6d20eed066a3b565756ad83888d22 |
| s390: | |
| httpd-2.0.52-12.2.ent.s390.rpm | 0cbd52d64a91644717a1df0e15ccc39a |
| httpd-devel-2.0.52-12.2.ent.s390.rpm | ca79cb435376a78d9f6b33c83473defe |
| httpd-manual-2.0.52-12.2.ent.s390.rpm | 3e8a5481d36c837350b17ee20c4fd429 |
| httpd-suexec-2.0.52-12.2.ent.s390.rpm | 2899ee38bcd82766e731b57d3330ce9a |
| mod_ssl-2.0.52-12.2.ent.s390.rpm | 7b5f79e871aefd2482c18cff9904c7c4 |
| s390x: | |
| httpd-2.0.52-12.2.ent.s390x.rpm | ca68a1ae7ab25f761c901f28cd522f74 |
| httpd-devel-2.0.52-12.2.ent.s390x.rpm | 09c838209a62cba64e5b28688e313026 |
| httpd-manual-2.0.52-12.2.ent.s390x.rpm | caf032aaba9e03987ba1413743c47088 |
| httpd-suexec-2.0.52-12.2.ent.s390x.rpm | 0eeea0d60e789902f10252c39b13140a |
| mod_ssl-2.0.52-12.2.ent.s390x.rpm | cedd7dadf3408b281a9d4d7d45e31b16 |
| x86_64: | |
| httpd-2.0.52-12.2.ent.x86_64.rpm | 34ec39c05630e576fad8859e8f233ba7 |
| httpd-devel-2.0.52-12.2.ent.x86_64.rpm | 614164cb0770a14d30eacc211fed4242 |
| httpd-manual-2.0.52-12.2.ent.x86_64.rpm | 2b59b10e2c8e41ed23041e3d433a67c7 |
| httpd-suexec-2.0.52-12.2.ent.x86_64.rpm | 2ce9c581b49e48da9db9b95e61f18ea9 |
| mod_ssl-2.0.52-12.2.ent.x86_64.rpm | 048f5c406bac99d9026eca82573c59f1 |
| Red Hat Enterprise Linux ES (v. 3) | |
| SRPMS: | |
| httpd-2.0.46-46.3.ent.src.rpm | 484b418c080a8fc60b3add4dfcf1900f |
| IA-32: | |
| httpd-2.0.46-46.3.ent.i386.rpm | 319460633151ee1517c8148931ca72de |
| httpd-devel-2.0.46-46.3.ent.i386.rpm | 6cc3044405158920afedbd288430544c |
| mod_ssl-2.0.46-46.3.ent.i386.rpm | ee51eb393a77fcbc28640ab9c7c0376c |
| IA-64: | |
| httpd-2.0.46-46.3.ent.ia64.rpm | 5f9c92619f6a7e60409aeef7b92f5056 |
| httpd-devel-2.0.46-46.3.ent.ia64.rpm | cba1acc27a9904ea4988159c81e96a97 |
| mod_ssl-2.0.46-46.3.ent.ia64.rpm | 15b4dba781df66f9cbcfc0230b96d261 |
| x86_64: | |
| httpd-2.0.46-46.3.ent.x86_64.rpm | d1bd5698951993680a3f4d78b332117e |
| httpd-devel-2.0.46-46.3.ent.x86_64.rpm | 9d57852140e597b4719cda1d8aee4101 |
| mod_ssl-2.0.46-46.3.ent.x86_64.rpm | fc4beccd061aa1de3286a4548d820bcc |
| Red Hat Enterprise Linux ES (v. 4) | |
| SRPMS: | |
| httpd-2.0.52-12.2.ent.src.rpm | de6c9583b0be4f8a91d58f9d96082d3c |
| IA-32: | |
| httpd-2.0.52-12.2.ent.i386.rpm | 2b535c428cc468bb8c94e88cb47b48a0 |
| httpd-devel-2.0.52-12.2.ent.i386.rpm | 62933dc89da98cf4e2cdb885cb195d29 |
| httpd-manual-2.0.52-12.2.ent.i386.rpm | 573ee8e079b51dd2d6a474c7513ede63 |
| httpd-suexec-2.0.52-12.2.ent.i386.rpm | ee7ce0885eb313d0f359c89b0d22b637 |
| mod_ssl-2.0.52-12.2.ent.i386.rpm | df4a617088e7c3d22cdb88d149f81209 |
| IA-64: | |
| httpd-2.0.52-12.2.ent.ia64.rpm | 2c03808a9cf8081f395259ae21730af0 |
| httpd-devel-2.0.52-12.2.ent.ia64.rpm | 99fcf9f0c7ea2b8a4248cd3a0d25da89 |
| httpd-manual-2.0.52-12.2.ent.ia64.rpm | 856092d56cc712997901f534a76f568c |
| httpd-suexec-2.0.52-12.2.ent.ia64.rpm | 92ac8b5beb4e12b1ead63f7027d07cfb |
| mod_ssl-2.0.52-12.2.ent.ia64.rpm | a44cc800809c368c7455c1af306b8e7d |
| x86_64: | |
| httpd-2.0.52-12.2.ent.x86_64.rpm | 34ec39c05630e576fad8859e8f233ba7 |
| httpd-devel-2.0.52-12.2.ent.x86_64.rpm | 614164cb0770a14d30eacc211fed4242 |
| httpd-manual-2.0.52-12.2.ent.x86_64.rpm | 2b59b10e2c8e41ed23041e3d433a67c7 |
| httpd-suexec-2.0.52-12.2.ent.x86_64.rpm | 2ce9c581b49e48da9db9b95e61f18ea9 |
| mod_ssl-2.0.52-12.2.ent.x86_64.rpm | 048f5c406bac99d9026eca82573c59f1 |
| Red Hat Enterprise Linux WS (v. 3) | |
| SRPMS: | |
| httpd-2.0.46-46.3.ent.src.rpm | 484b418c080a8fc60b3add4dfcf1900f |
| IA-32: | |
| httpd-2.0.46-46.3.ent.i386.rpm | 319460633151ee1517c8148931ca72de |
| httpd-devel-2.0.46-46.3.ent.i386.rpm | 6cc3044405158920afedbd288430544c |
| mod_ssl-2.0.46-46.3.ent.i386.rpm | ee51eb393a77fcbc28640ab9c7c0376c |
| IA-64: | |
| httpd-2.0.46-46.3.ent.ia64.rpm | 5f9c92619f6a7e60409aeef7b92f5056 |
| httpd-devel-2.0.46-46.3.ent.ia64.rpm | cba1acc27a9904ea4988159c81e96a97 |
| mod_ssl-2.0.46-46.3.ent.ia64.rpm | 15b4dba781df66f9cbcfc0230b96d261 |
| x86_64: | |
| httpd-2.0.46-46.3.ent.x86_64.rpm | d1bd5698951993680a3f4d78b332117e |
| httpd-devel-2.0.46-46.3.ent.x86_64.rpm | 9d57852140e597b4719cda1d8aee4101 |
| mod_ssl-2.0.46-46.3.ent.x86_64.rpm | fc4beccd061aa1de3286a4548d820bcc |
| Red Hat Enterprise Linux WS (v. 4) | |
| SRPMS: | |
| httpd-2.0.52-12.2.ent.src.rpm | de6c9583b0be4f8a91d58f9d96082d3c |
| IA-32: | |
| httpd-2.0.52-12.2.ent.i386.rpm | 2b535c428cc468bb8c94e88cb47b48a0 |
| httpd-devel-2.0.52-12.2.ent.i386.rpm | 62933dc89da98cf4e2cdb885cb195d29 |
| httpd-manual-2.0.52-12.2.ent.i386.rpm | 573ee8e079b51dd2d6a474c7513ede63 |
| httpd-suexec-2.0.52-12.2.ent.i386.rpm | ee7ce0885eb313d0f359c89b0d22b637 |
| mod_ssl-2.0.52-12.2.ent.i386.rpm | df4a617088e7c3d22cdb88d149f81209 |
| IA-64: | |
| httpd-2.0.52-12.2.ent.ia64.rpm | 2c03808a9cf8081f395259ae21730af0 |
| httpd-devel-2.0.52-12.2.ent.ia64.rpm | 99fcf9f0c7ea2b8a4248cd3a0d25da89 |
| httpd-manual-2.0.52-12.2.ent.ia64.rpm | 856092d56cc712997901f534a76f568c |
| httpd-suexec-2.0.52-12.2.ent.ia64.rpm | 92ac8b5beb4e12b1ead63f7027d07cfb |
| mod_ssl-2.0.52-12.2.ent.ia64.rpm | a44cc800809c368c7455c1af306b8e7d |
| x86_64: | |
| httpd-2.0.52-12.2.ent.x86_64.rpm | 34ec39c05630e576fad8859e8f233ba7 |
| httpd-devel-2.0.52-12.2.ent.x86_64.rpm | 614164cb0770a14d30eacc211fed4242 |
| httpd-manual-2.0.52-12.2.ent.x86_64.rpm | 2b59b10e2c8e41ed23041e3d433a67c7 |
| httpd-suexec-2.0.52-12.2.ent.x86_64.rpm | 2ce9c581b49e48da9db9b95e61f18ea9 |
| mod_ssl-2.0.52-12.2.ent.x86_64.rpm | 048f5c406bac99d9026eca82573c59f1 |
| (The unlinked packages above are only available from the Red Hat Network) | |
解決法:
このアップデートを適用する前に、システムに関連するリリース済の errata が適用済であることをご確認ください。バグジラ: (詳細は、こちらbugzilla[英語]を御覧ください。)
167102 - CAN-2005-2728 byterange memory DoS
167194 - CAN-2005-2700 SSLVerifyClient flaw
参照:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2700キーワード:
apache, asf
ここに在るパッケージはセキュリティの為、 Red Hat, Inc. によって、 GPG 認証されています。キーは以下から利用可能になっています:
http://www.redhat.com/about/contact.html
各パッケージを確認するには次のコマンドをご利用ください: rpm --checksig filename
各パッケージが壊れていないか、もしくは改ざんされていないかを確認するには、以下のコマンドで MD5 チェックサムをお調べください: rpm --checksig --nogpg filename
注意: GnuPG キーをチェックするためには、RPM 3.0 以上が必要です。