低(Low):opensshのセキュリティアップデート
セキュリティ・アドバイス
概要:
認証の欠陥を修正したopensshのアップデートパッケージがRed Hat Enterprise Linux 3および4で利用可能になりました。
このアップデートは、レッドハットセキュリティ対策チームによって、深刻度「低(low)」のセキュリティ問題と評価されています。
OpenSSHは、OpenBSDのSSH(Secure SHell)プロトコル実装です。このパッケージには、OpenSSHのクライアントとサーバの両方に必要なコアファイルが含まれています。
OpenSSHの特権分離モニタで認証の欠陥が見つかりました。OpenSSHで特権分離を使用しているときに特権のないプロセスの動作を変更することが可能になった場合、正しい証明書を持たない攻撃者がログインできることがあります。(CVE-2006-5794)
この欠陥は、単独ではOpenSSHユーザに直接脅威を与えることはありません。攻撃者がOpenSSHの特権のないプロセスの動作を変更できるような別のセキュリティ欠陥が存在しなければ、この欠陥を悪用することはできません。現在のところ、この動作を悪用できるような既知の欠陥はありません。しかし、特権のないプロセスの欠陥が見つかった場合のセキュリティ上の影響を軽減するために、本エラータを発行してこの 欠陥を修正することが決定されました。
opensshのユーザは、この問題を解決するバックポートパッチを含む上記アップデートパッケージにアップグレードしてください。
アップデート・パッケージ:
| Red Hat Desktop (v. 3) | |
| SRPMS: | |
| openssh-3.6.1p2-33.30.13.src.rpm | b4e08619ea23f2af0429645d98639bd2 |
| IA-32: | |
| openssh-3.6.1p2-33.30.13.i386.rpm | dcd132e60b59e7a7fd75ac15f55b7207 |
| openssh-askpass-3.6.1p2-33.30.13.i386.rpm | f1e4ab33051a26303ecf5c8d0fa6d779 |
| openssh-askpass-gnome-3.6.1p2-33.30.13.i386.rpm | 7fe0c43c9178918e47af5b6cf7a53e50 |
| openssh-clients-3.6.1p2-33.30.13.i386.rpm | 53cbe1ce4743e7986ec6ca28c61c4941 |
| openssh-server-3.6.1p2-33.30.13.i386.rpm | e067fb1660d69db52438fd942b18b238 |
| x86_64: | |
| openssh-3.6.1p2-33.30.13.x86_64.rpm | 881bb14daa2f11d4ccbf6b2479df1074 |
| openssh-askpass-3.6.1p2-33.30.13.x86_64.rpm | 52a84e68e0900fa418a61f72ddb1c531 |
| openssh-askpass-gnome-3.6.1p2-33.30.13.x86_64.rpm | a621607fdbaafd4c58aa3627eeee5fe9 |
| openssh-clients-3.6.1p2-33.30.13.x86_64.rpm | 84688b731d914ad46b35afb375aacd5f |
| openssh-server-3.6.1p2-33.30.13.x86_64.rpm | 6e95eef8d383b8fe4f21dc64eebbd3cf |
| Red Hat Desktop (v. 4) | |
| SRPMS: | |
| openssh-3.9p1-8.RHEL4.17.1.src.rpm | 5270fb8ec13f23828a277857ae68b986 |
| IA-32: | |
| openssh-3.9p1-8.RHEL4.17.1.i386.rpm | 8b1c7fbd0bf72ceb0b2f5eda16d3fa5d |
| openssh-askpass-3.9p1-8.RHEL4.17.1.i386.rpm | 79f74f20a37e5e5d9f88bfc80927d201 |
| openssh-askpass-gnome-3.9p1-8.RHEL4.17.1.i386.rpm | 96db1c1a17e9348677f8d0eaf7d99116 |
| openssh-clients-3.9p1-8.RHEL4.17.1.i386.rpm | f349608f4e1e588f8c544564319f6388 |
| openssh-server-3.9p1-8.RHEL4.17.1.i386.rpm | 2c021513b7f7d86783342293d0a229e0 |
| x86_64: | |
| openssh-3.9p1-8.RHEL4.17.1.x86_64.rpm | 0ce295c848385f2a25fa17ae7c0beb52 |
| openssh-askpass-3.9p1-8.RHEL4.17.1.x86_64.rpm | 826459d7ddfb2b39e718cbb303f246bb |
| openssh-askpass-gnome-3.9p1-8.RHEL4.17.1.x86_64.rpm | 3d56f032c9ab9d15327173acad692f93 |
| openssh-clients-3.9p1-8.RHEL4.17.1.x86_64.rpm | 7076713a1e1732e10a66be5dcdea4faa |
| openssh-server-3.9p1-8.RHEL4.17.1.x86_64.rpm | 3a7c7aa5c2378ac7c2954ff17acfca19 |
| Red Hat Enterprise Linux AS (v. 3) | |
| SRPMS: | |
| openssh-3.6.1p2-33.30.13.src.rpm | b4e08619ea23f2af0429645d98639bd2 |
| IA-32: | |
| openssh-3.6.1p2-33.30.13.i386.rpm | dcd132e60b59e7a7fd75ac15f55b7207 |
| openssh-askpass-3.6.1p2-33.30.13.i386.rpm | f1e4ab33051a26303ecf5c8d0fa6d779 |
| openssh-askpass-gnome-3.6.1p2-33.30.13.i386.rpm | 7fe0c43c9178918e47af5b6cf7a53e50 |
| openssh-clients-3.6.1p2-33.30.13.i386.rpm | 53cbe1ce4743e7986ec6ca28c61c4941 |
| openssh-server-3.6.1p2-33.30.13.i386.rpm | e067fb1660d69db52438fd942b18b238 |
| IA-64: | |
| openssh-3.6.1p2-33.30.13.ia64.rpm | 908a742ccbce2dc3633094328135143d |
| openssh-askpass-3.6.1p2-33.30.13.ia64.rpm | 3c81416cf2bb3e95a1df43cdb789f1d9 |
| openssh-askpass-gnome-3.6.1p2-33.30.13.ia64.rpm | ec530b9aae551ad18982fd7c88ea46c5 |
| openssh-clients-3.6.1p2-33.30.13.ia64.rpm | 21c01f4d6e41be485e0f4f0866c0bcab |
| openssh-server-3.6.1p2-33.30.13.ia64.rpm | 52dc05f6756942bb9cd36d652c3e0cb2 |
| PPC: | |
| openssh-3.6.1p2-33.30.13.ppc.rpm | 74d7a40819ac28ffe57b4d0358637aa5 |
| openssh-askpass-3.6.1p2-33.30.13.ppc.rpm | fb1b5891efc8fb9db26f989b48f7df9f |
| openssh-askpass-gnome-3.6.1p2-33.30.13.ppc.rpm | 30c4c779e67f9f140c1ba818d16b3389 |
| openssh-clients-3.6.1p2-33.30.13.ppc.rpm | 42654616ea74a154c8ec943ce0c99ced |
| openssh-server-3.6.1p2-33.30.13.ppc.rpm | dfca8ed1c115ea29121a6a75852d32a7 |
| s390: | |
| openssh-3.6.1p2-33.30.13.s390.rpm | 047c99c9d1f0a8302f3c0a751da3f99a |
| openssh-askpass-3.6.1p2-33.30.13.s390.rpm | 2dab72bc1e5f9f54b4e9caf201f9f617 |
| openssh-askpass-gnome-3.6.1p2-33.30.13.s390.rpm | 1dd2d0fdf4f8abf1b7fb839ff611dff1 |
| openssh-clients-3.6.1p2-33.30.13.s390.rpm | fda4dabc8b23e7f860766f8412b7abf7 |
| openssh-server-3.6.1p2-33.30.13.s390.rpm | fccc35c776978fe2654e7fbba3461dbf |
| s390x: | |
| openssh-3.6.1p2-33.30.13.s390x.rpm | e92b4ce6f01fca8daca17c7787253ce6 |
| openssh-askpass-3.6.1p2-33.30.13.s390x.rpm | b600a2739c93ecdb6e43821d1bafe16f |
| openssh-askpass-gnome-3.6.1p2-33.30.13.s390x.rpm | 56bb8de4d2423ee720bbfea87274a40e |
| openssh-clients-3.6.1p2-33.30.13.s390x.rpm | 5a4a37e51b6f7a0f36a698b5cc833628 |
| openssh-server-3.6.1p2-33.30.13.s390x.rpm | 518f3d002574064fe0401d724df50abd |
| x86_64: | |
| openssh-3.6.1p2-33.30.13.x86_64.rpm | 881bb14daa2f11d4ccbf6b2479df1074 |
| openssh-askpass-3.6.1p2-33.30.13.x86_64.rpm | 52a84e68e0900fa418a61f72ddb1c531 |
| openssh-askpass-gnome-3.6.1p2-33.30.13.x86_64.rpm | a621607fdbaafd4c58aa3627eeee5fe9 |
| openssh-clients-3.6.1p2-33.30.13.x86_64.rpm | 84688b731d914ad46b35afb375aacd5f |
| openssh-server-3.6.1p2-33.30.13.x86_64.rpm | 6e95eef8d383b8fe4f21dc64eebbd3cf |
| Red Hat Enterprise Linux AS (v. 4) | |
| SRPMS: | |
| openssh-3.9p1-8.RHEL4.17.1.src.rpm | 5270fb8ec13f23828a277857ae68b986 |
| IA-32: | |
| openssh-3.9p1-8.RHEL4.17.1.i386.rpm | 8b1c7fbd0bf72ceb0b2f5eda16d3fa5d |
| openssh-askpass-3.9p1-8.RHEL4.17.1.i386.rpm | 79f74f20a37e5e5d9f88bfc80927d201 |
| openssh-askpass-gnome-3.9p1-8.RHEL4.17.1.i386.rpm | 96db1c1a17e9348677f8d0eaf7d99116 |
| openssh-clients-3.9p1-8.RHEL4.17.1.i386.rpm | f349608f4e1e588f8c544564319f6388 |
| openssh-server-3.9p1-8.RHEL4.17.1.i386.rpm | 2c021513b7f7d86783342293d0a229e0 |
| IA-64: | |
| openssh-3.9p1-8.RHEL4.17.1.ia64.rpm | 9f7af45fa7b5a5960dae6481797df65f |
| openssh-askpass-3.9p1-8.RHEL4.17.1.ia64.rpm | 396afde30d013dc3b99473070c9ca016 |
| openssh-askpass-gnome-3.9p1-8.RHEL4.17.1.ia64.rpm | 05504a84c2ef6cd7eb50e8044d537733 |
| openssh-clients-3.9p1-8.RHEL4.17.1.ia64.rpm | 85931af336574b468781c5348c5be257 |
| openssh-server-3.9p1-8.RHEL4.17.1.ia64.rpm | 90098e9f32a04b29e707cc0b3716d438 |
| PPC: | |
| openssh-3.9p1-8.RHEL4.17.1.ppc.rpm | 2af4e90aa5c152ab51bae154ab54d69c |
| openssh-askpass-3.9p1-8.RHEL4.17.1.ppc.rpm | b6433ae6bb5b320b16b1970aaad929b1 |
| openssh-askpass-gnome-3.9p1-8.RHEL4.17.1.ppc.rpm | 246880b444305e3e2781ae06f6b0af4b |
| openssh-clients-3.9p1-8.RHEL4.17.1.ppc.rpm | c4cc7545bc8c4e68f9efc14cbee42069 |
| openssh-server-3.9p1-8.RHEL4.17.1.ppc.rpm | 0232045e1c230a1cb37ba40f44f4ec96 |
| s390: | |
| openssh-3.9p1-8.RHEL4.17.1.s390.rpm | d3ca921e20d2ed9af35eaba73baa434d |
| openssh-askpass-3.9p1-8.RHEL4.17.1.s390.rpm | 2bac8f50617955b5be6173b0b386f270 |
| openssh-askpass-gnome-3.9p1-8.RHEL4.17.1.s390.rpm | f853497e2fb1124055b4d2bede7c56de |
| openssh-clients-3.9p1-8.RHEL4.17.1.s390.rpm | fd1d9c9aaa84763fb1ad4d93df7da3df |
| openssh-server-3.9p1-8.RHEL4.17.1.s390.rpm | 81c1dfd0f611b7509e2d715e0dc005f0 |
| s390x: | |
| openssh-3.9p1-8.RHEL4.17.1.s390x.rpm | 79767ede8be763dab8cf825dfb203374 |
| openssh-askpass-3.9p1-8.RHEL4.17.1.s390x.rpm | 1e1891b117b67d9ae272fefa96f0b2df |
| openssh-askpass-gnome-3.9p1-8.RHEL4.17.1.s390x.rpm | 5418dda31a691b7e1d86d367ae3e34cd |
| openssh-clients-3.9p1-8.RHEL4.17.1.s390x.rpm | f239e3313b6f50a5c75e1ffe86ecfde1 |
| openssh-server-3.9p1-8.RHEL4.17.1.s390x.rpm | 4d7d4015d1fa094b782079fcf046f887 |
| x86_64: | |
| openssh-3.9p1-8.RHEL4.17.1.x86_64.rpm | 0ce295c848385f2a25fa17ae7c0beb52 |
| openssh-askpass-3.9p1-8.RHEL4.17.1.x86_64.rpm | 826459d7ddfb2b39e718cbb303f246bb |
| openssh-askpass-gnome-3.9p1-8.RHEL4.17.1.x86_64.rpm | 3d56f032c9ab9d15327173acad692f93 |
| openssh-clients-3.9p1-8.RHEL4.17.1.x86_64.rpm | 7076713a1e1732e10a66be5dcdea4faa |
| openssh-server-3.9p1-8.RHEL4.17.1.x86_64.rpm | 3a7c7aa5c2378ac7c2954ff17acfca19 |
| Red Hat Enterprise Linux ES (v. 3) | |
| SRPMS: | |
| openssh-3.6.1p2-33.30.13.src.rpm | b4e08619ea23f2af0429645d98639bd2 |
| IA-32: | |
| openssh-3.6.1p2-33.30.13.i386.rpm | dcd132e60b59e7a7fd75ac15f55b7207 |
| openssh-askpass-3.6.1p2-33.30.13.i386.rpm | f1e4ab33051a26303ecf5c8d0fa6d779 |
| openssh-askpass-gnome-3.6.1p2-33.30.13.i386.rpm | 7fe0c43c9178918e47af5b6cf7a53e50 |
| openssh-clients-3.6.1p2-33.30.13.i386.rpm | 53cbe1ce4743e7986ec6ca28c61c4941 |
| openssh-server-3.6.1p2-33.30.13.i386.rpm | e067fb1660d69db52438fd942b18b238 |
| IA-64: | |
| openssh-3.6.1p2-33.30.13.ia64.rpm | 908a742ccbce2dc3633094328135143d |
| openssh-askpass-3.6.1p2-33.30.13.ia64.rpm | 3c81416cf2bb3e95a1df43cdb789f1d9 |
| openssh-askpass-gnome-3.6.1p2-33.30.13.ia64.rpm | ec530b9aae551ad18982fd7c88ea46c5 |
| openssh-clients-3.6.1p2-33.30.13.ia64.rpm | 21c01f4d6e41be485e0f4f0866c0bcab |
| openssh-server-3.6.1p2-33.30.13.ia64.rpm | 52dc05f6756942bb9cd36d652c3e0cb2 |
| x86_64: | |
| openssh-3.6.1p2-33.30.13.x86_64.rpm | 881bb14daa2f11d4ccbf6b2479df1074 |
| openssh-askpass-3.6.1p2-33.30.13.x86_64.rpm | 52a84e68e0900fa418a61f72ddb1c531 |
| openssh-askpass-gnome-3.6.1p2-33.30.13.x86_64.rpm | a621607fdbaafd4c58aa3627eeee5fe9 |
| openssh-clients-3.6.1p2-33.30.13.x86_64.rpm | 84688b731d914ad46b35afb375aacd5f |
| openssh-server-3.6.1p2-33.30.13.x86_64.rpm | 6e95eef8d383b8fe4f21dc64eebbd3cf |
| Red Hat Enterprise Linux ES (v. 4) | |
| SRPMS: | |
| openssh-3.9p1-8.RHEL4.17.1.src.rpm | 5270fb8ec13f23828a277857ae68b986 |
| IA-32: | |
| openssh-3.9p1-8.RHEL4.17.1.i386.rpm | 8b1c7fbd0bf72ceb0b2f5eda16d3fa5d |
| openssh-askpass-3.9p1-8.RHEL4.17.1.i386.rpm | 79f74f20a37e5e5d9f88bfc80927d201 |
| openssh-askpass-gnome-3.9p1-8.RHEL4.17.1.i386.rpm | 96db1c1a17e9348677f8d0eaf7d99116 |
| openssh-clients-3.9p1-8.RHEL4.17.1.i386.rpm | f349608f4e1e588f8c544564319f6388 |
| openssh-server-3.9p1-8.RHEL4.17.1.i386.rpm | 2c021513b7f7d86783342293d0a229e0 |
| IA-64: | |
| openssh-3.9p1-8.RHEL4.17.1.ia64.rpm | 9f7af45fa7b5a5960dae6481797df65f |
| openssh-askpass-3.9p1-8.RHEL4.17.1.ia64.rpm | 396afde30d013dc3b99473070c9ca016 |
| openssh-askpass-gnome-3.9p1-8.RHEL4.17.1.ia64.rpm | 05504a84c2ef6cd7eb50e8044d537733 |
| openssh-clients-3.9p1-8.RHEL4.17.1.ia64.rpm | 85931af336574b468781c5348c5be257 |
| openssh-server-3.9p1-8.RHEL4.17.1.ia64.rpm | 90098e9f32a04b29e707cc0b3716d438 |
| x86_64: | |
| openssh-3.9p1-8.RHEL4.17.1.x86_64.rpm | 0ce295c848385f2a25fa17ae7c0beb52 |
| openssh-askpass-3.9p1-8.RHEL4.17.1.x86_64.rpm | 826459d7ddfb2b39e718cbb303f246bb |
| openssh-askpass-gnome-3.9p1-8.RHEL4.17.1.x86_64.rpm | 3d56f032c9ab9d15327173acad692f93 |
| openssh-clients-3.9p1-8.RHEL4.17.1.x86_64.rpm | 7076713a1e1732e10a66be5dcdea4faa |
| openssh-server-3.9p1-8.RHEL4.17.1.x86_64.rpm | 3a7c7aa5c2378ac7c2954ff17acfca19 |
| Red Hat Enterprise Linux WS (v. 3) | |
| SRPMS: | |
| openssh-3.6.1p2-33.30.13.src.rpm | b4e08619ea23f2af0429645d98639bd2 |
| IA-32: | |
| openssh-3.6.1p2-33.30.13.i386.rpm | dcd132e60b59e7a7fd75ac15f55b7207 |
| openssh-askpass-3.6.1p2-33.30.13.i386.rpm | f1e4ab33051a26303ecf5c8d0fa6d779 |
| openssh-askpass-gnome-3.6.1p2-33.30.13.i386.rpm | 7fe0c43c9178918e47af5b6cf7a53e50 |
| openssh-clients-3.6.1p2-33.30.13.i386.rpm | 53cbe1ce4743e7986ec6ca28c61c4941 |
| openssh-server-3.6.1p2-33.30.13.i386.rpm | e067fb1660d69db52438fd942b18b238 |
| IA-64: | |
| openssh-3.6.1p2-33.30.13.ia64.rpm | 908a742ccbce2dc3633094328135143d |
| openssh-askpass-3.6.1p2-33.30.13.ia64.rpm | 3c81416cf2bb3e95a1df43cdb789f1d9 |
| openssh-askpass-gnome-3.6.1p2-33.30.13.ia64.rpm | ec530b9aae551ad18982fd7c88ea46c5 |
| openssh-clients-3.6.1p2-33.30.13.ia64.rpm | 21c01f4d6e41be485e0f4f0866c0bcab |
| openssh-server-3.6.1p2-33.30.13.ia64.rpm | 52dc05f6756942bb9cd36d652c3e0cb2 |
| x86_64: | |
| openssh-3.6.1p2-33.30.13.x86_64.rpm | 881bb14daa2f11d4ccbf6b2479df1074 |
| openssh-askpass-3.6.1p2-33.30.13.x86_64.rpm | 52a84e68e0900fa418a61f72ddb1c531 |
| openssh-askpass-gnome-3.6.1p2-33.30.13.x86_64.rpm | a621607fdbaafd4c58aa3627eeee5fe9 |
| openssh-clients-3.6.1p2-33.30.13.x86_64.rpm | 84688b731d914ad46b35afb375aacd5f |
| openssh-server-3.6.1p2-33.30.13.x86_64.rpm | 6e95eef8d383b8fe4f21dc64eebbd3cf |
| Red Hat Enterprise Linux WS (v. 4) | |
| SRPMS: | |
| openssh-3.9p1-8.RHEL4.17.1.src.rpm | 5270fb8ec13f23828a277857ae68b986 |
| IA-32: | |
| openssh-3.9p1-8.RHEL4.17.1.i386.rpm | 8b1c7fbd0bf72ceb0b2f5eda16d3fa5d |
| openssh-askpass-3.9p1-8.RHEL4.17.1.i386.rpm | 79f74f20a37e5e5d9f88bfc80927d201 |
| openssh-askpass-gnome-3.9p1-8.RHEL4.17.1.i386.rpm | 96db1c1a17e9348677f8d0eaf7d99116 |
| openssh-clients-3.9p1-8.RHEL4.17.1.i386.rpm | f349608f4e1e588f8c544564319f6388 |
| openssh-server-3.9p1-8.RHEL4.17.1.i386.rpm | 2c021513b7f7d86783342293d0a229e0 |
| IA-64: | |
| openssh-3.9p1-8.RHEL4.17.1.ia64.rpm | 9f7af45fa7b5a5960dae6481797df65f |
| openssh-askpass-3.9p1-8.RHEL4.17.1.ia64.rpm | 396afde30d013dc3b99473070c9ca016 |
| openssh-askpass-gnome-3.9p1-8.RHEL4.17.1.ia64.rpm | 05504a84c2ef6cd7eb50e8044d537733 |
| openssh-clients-3.9p1-8.RHEL4.17.1.ia64.rpm | 85931af336574b468781c5348c5be257 |
| openssh-server-3.9p1-8.RHEL4.17.1.ia64.rpm | 90098e9f32a04b29e707cc0b3716d438 |
| x86_64: | |
| openssh-3.9p1-8.RHEL4.17.1.x86_64.rpm | 0ce295c848385f2a25fa17ae7c0beb52 |
| openssh-askpass-3.9p1-8.RHEL4.17.1.x86_64.rpm | 826459d7ddfb2b39e718cbb303f246bb |
| openssh-askpass-gnome-3.9p1-8.RHEL4.17.1.x86_64.rpm | 3d56f032c9ab9d15327173acad692f93 |
| openssh-clients-3.9p1-8.RHEL4.17.1.x86_64.rpm | 7076713a1e1732e10a66be5dcdea4faa |
| openssh-server-3.9p1-8.RHEL4.17.1.x86_64.rpm | 3a7c7aa5c2378ac7c2954ff17acfca19 |
| (The unlinked packages above are only available from the Red Hat Network) | |
解決法:
このアップデートを適用する前に、システムに関連するリリース済の errata が適用済であることをご確認ください。バグジラ: (詳細は、こちらbugzilla[英語]を御覧ください。)
214640 - CVE-2006-5794 OpenSSH privilege separation flaw
参照:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5794
ここに在るパッケージはセキュリティの為、 Red Hat, Inc. によって、 GPG 認証されています。キーは以下から利用可能になっています:
http://www.redhat.com/about/contact.html
各パッケージを確認するには次のコマンドをご利用ください: rpm --checksig filename
各パッケージが壊れていないか、もしくは改ざんされていないかを確認するには、以下のコマンドで MD5 チェックサムをお調べください: rpm --checksig --nogpg filename
注意: GnuPG キーをチェックするためには、RPM 3.0 以上が必要です。