[轉錄]【TWCERT/CC安全通報】TW-CA-2005-018-[RHSA-2005:069-01: Upd

看板NetSecurity (資安 資訊安全)作者時間21年前 (2005/02/17 17:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
-----BEGIN PGP SIGNED MESSAGE----- TW-CA-2005-018-[RHSA-2005:069-01: Updated perl-DBI package fixes security issue] ──────────────────────────────────────── TWCERT/CC發布日期:2005-02-17 原漏洞發布日期:2005-02-01 原漏洞最新更新日期:-- 通用安全漏洞編號:CAN-2005-0077 分類:Gain Privilege 來源參考:RHSA-2005:069-01 ──── 簡述 ───────────────────────────────── 更新 perl-DBI 套件,修正 DBI::ProxyServer 中暫存檔的漏洞。 ──── 說明 ───────────────────────────────── DBI 是適用 Perl 程式語言的資料庫存取應用程式介面 (API)。 DBI 程式庫會產生不安全的暫存 PID 檔。本地端使用者可以不同使用者的身份複寫或產生 檔案。CVE (cve.mitre.org) 已將此問題命名為 CAN-2005-0077。 建議使用者更新此勘誤套件,可取消 PID 暫存檔的功能。 ──── 影響平台 ─────────────────────────────── ‧Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 ‧Red Hat Linux Advanced Workstation 2.1 - ia64 ‧Red Hat Enterprise Linux ES version 2.1 - i386 ‧Red Hat Enterprise Linux WS version 2.1 - i386 ‧Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 ‧Red Hat Desktop version 3 - i386, x86_64 ‧Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 ‧Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 ──── 修正方式 ─────────────────────────────── 在安裝更新之前,確定已安裝之前所有跟系統相關的錯誤修正。使用 Red Hat Network 來 下載及更新套件,輸入以下指令啟動 Red Hat Update Agent: up2date 若要獲得更多手動安裝套件的資訊,請參閱下面網址,尋求適合您系統的指引手冊: http://www.redhat.com/docs/manuals/enterprise/ Bug IDs fixed(詳見 http://bugzilla.redhat.com/): 145577 - CAN-2005-0077 perl-DBI insecure temporary file usage RPM 需求: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: ftp://updates.redhat.com/enterprise/2.1AS/en/os/SRPMS/perl-DBI-1.18-3.src.rpm b614c046679c98e6cee4b3ef143aff6e perl-DBI-1.18-3.src.rpm i386: 22af0266ecb99d0997a2d9f245e3a048 perl-DBI-1.18-3.i386.rpm ia64: c77842c2d3164aaaccbdbc835b28834b perl-DBI-1.18-3.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: ftp://updates.redhat.com/enterprise/2.1AW/en/os/SRPMS/perl-DBI-1.18-3.src.rpm b614c046679c98e6cee4b3ef143aff6e perl-DBI-1.18-3.src.rpm ia64: c77842c2d3164aaaccbdbc835b28834b perl-DBI-1.18-3.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: ftp://updates.redhat.com/enterprise/2.1ES/en/os/SRPMS/perl-DBI-1.18-3.src.rpm b614c046679c98e6cee4b3ef143aff6e perl-DBI-1.18-3.src.rpm i386: 22af0266ecb99d0997a2d9f245e3a048 perl-DBI-1.18-3.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: ftp://updates.redhat.com/enterprise/2.1WS/en/os/SRPMS/perl-DBI-1.18-3.src.rpm b614c046679c98e6cee4b3ef143aff6e perl-DBI-1.18-3.src.rpm i386: 22af0266ecb99d0997a2d9f245e3a048 perl-DBI-1.18-3.i386.rpm Red Hat Enterprise Linux AS version 3: SRPMS: ftp://updates.redhat.com/enterprise/3AS/en/os/SRPMS/perl-DBI-1.32-9.src.rpm eabf3cd83dd61c9b09d2bb6e2160755a perl-DBI-1.32-9.src.rpm i386: 6aea6d47ab2a26300af6ed577405e6b7 perl-DBI-1.32-9.i386.rpm ia64: 9f9dbb9313e84f86908b00aeb737c424 perl-DBI-1.32-9.ia64.rpm ppc: ff90be122c3636ba3b2b253428092633 perl-DBI-1.32-9.ppc.rpm s390: fc8faf4640441c1b5cd77972a23ac4ec perl-DBI-1.32-9.s390.rpm s390x: 371823a6fb25f64dd773073c814d513b perl-DBI-1.32-9.s390x.rpm x86_64: 86936f627f02c8f96da5467c536997e6 perl-DBI-1.32-9.x86_64.rpm Red Hat Desktop version 3: SRPMS: ftp://updates.redhat.com/enterprise/3desktop/en/os/SRPMS/perl-DBI-1.32-9.src.rpm eabf3cd83dd61c9b09d2bb6e2160755a perl-DBI-1.32-9.src.rpm i386: 6aea6d47ab2a26300af6ed577405e6b7 perl-DBI-1.32-9.i386.rpm x86_64: 86936f627f02c8f96da5467c536997e6 perl-DBI-1.32-9.x86_64.rpm Red Hat Enterprise Linux ES version 3: SRPMS: ftp://updates.redhat.com/enterprise/3ES/en/os/SRPMS/perl-DBI-1.32-9.src.rpm eabf3cd83dd61c9b09d2bb6e2160755a perl-DBI-1.32-9.src.rpm i386: 6aea6d47ab2a26300af6ed577405e6b7 perl-DBI-1.32-9.i386.rpm ia64: 9f9dbb9313e84f86908b00aeb737c424 perl-DBI-1.32-9.ia64.rpm x86_64: 86936f627f02c8f96da5467c536997e6 perl-DBI-1.32-9.x86_64.rpm Red Hat Enterprise Linux WS version 3: SRPMS: ftp://updates.redhat.com/enterprise/3WS/en/os/SRPMS/perl-DBI-1.32-9.src.rpm eabf3cd83dd61c9b09d2bb6e2160755a perl-DBI-1.32-9.src.rpm i386: 6aea6d47ab2a26300af6ed577405e6b7 perl-DBI-1.32-9.i386.rpm ia64: 9f9dbb9313e84f86908b00aeb737c424 perl-DBI-1.32-9.ia64.rpm x86_64: 86936f627f02c8f96da5467c536997e6 perl-DBI-1.32-9.x86_64.rpm 這些套件基於安全理由,均由 Red Hat 公司使用 GPG 簽章,可至下列網址取得 key: https://www.redhat.com/security/team/key.html#package ──── 影響結果 ─────────────────────────────── ──── 聯絡TWCERT/CC ───────────────────────────── Tel: 886-7-5250211 FAX: 886-7-5250212 886-2-23563303 886-2-23924082 Email: twcert@cert.org.tw URL: http://www.cert.org.tw/ PGP key: http://www.cert.org.tw/eng/pgp.htm ──────────────────────────────────────── 附件:[Updated perl-DBI package fixes security issue] ──── 原文 ───────────────────────────────── - - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated perl-DBI package fixes security issue Advisory ID: RHSA-2005:069-01 Advisory URL: https://rhn.redhat.com/errata/RHSA-2005-069.html Issue date: 2005-02-01 Updated on: 2005-02-01 Product: Red Hat Enterprise Linux CVE Names: CAN-2005-0077 - - --------------------------------------------------------------------- 1. Summary: An updated perl-DBI package that fixes a temporary file flaw in DBI::ProxyServer is now available. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 3. Problem description: DBI is a database access Application Programming Interface (API) for the Perl programming language. The Debian Security Audit Project discovered that the DBI library creates a temporary PID file in an insecure manner. A local user could overwrite or create files as a different user who happens to run an application which uses DBI::ProxyServer. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0077 to this issue. Users should update to this erratum package which disables the temporary PID file unless configured. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: http://www.redhat.com/docs/manuals/enterprise/ 5. Bug IDs fixed (http://bugzilla.redhat.com/): 145577 - CAN-2005-0077 perl-DBI insecure temporary file usage 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: ftp://updates.redhat.com/enterprise/2.1AS/en/os/SRPMS/perl-DBI-1.18-3.src.rpm b614c046679c98e6cee4b3ef143aff6e perl-DBI-1.18-3.src.rpm i386: 22af0266ecb99d0997a2d9f245e3a048 perl-DBI-1.18-3.i386.rpm ia64: c77842c2d3164aaaccbdbc835b28834b perl-DBI-1.18-3.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: ftp://updates.redhat.com/enterprise/2.1AW/en/os/SRPMS/perl-DBI-1.18-3.src.rpm b614c046679c98e6cee4b3ef143aff6e perl-DBI-1.18-3.src.rpm ia64: c77842c2d3164aaaccbdbc835b28834b perl-DBI-1.18-3.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: ftp://updates.redhat.com/enterprise/2.1ES/en/os/SRPMS/perl-DBI-1.18-3.src.rpm b614c046679c98e6cee4b3ef143aff6e perl-DBI-1.18-3.src.rpm i386: 22af0266ecb99d0997a2d9f245e3a048 perl-DBI-1.18-3.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: ftp://updates.redhat.com/enterprise/2.1WS/en/os/SRPMS/perl-DBI-1.18-3.src.rpm b614c046679c98e6cee4b3ef143aff6e perl-DBI-1.18-3.src.rpm i386: 22af0266ecb99d0997a2d9f245e3a048 perl-DBI-1.18-3.i386.rpm Red Hat Enterprise Linux AS version 3: SRPMS: ftp://updates.redhat.com/enterprise/3AS/en/os/SRPMS/perl-DBI-1.32-9.src.rpm eabf3cd83dd61c9b09d2bb6e2160755a perl-DBI-1.32-9.src.rpm i386: 6aea6d47ab2a26300af6ed577405e6b7 perl-DBI-1.32-9.i386.rpm ia64: 9f9dbb9313e84f86908b00aeb737c424 perl-DBI-1.32-9.ia64.rpm ppc: ff90be122c3636ba3b2b253428092633 perl-DBI-1.32-9.ppc.rpm s390: fc8faf4640441c1b5cd77972a23ac4ec perl-DBI-1.32-9.s390.rpm s390x: 371823a6fb25f64dd773073c814d513b perl-DBI-1.32-9.s390x.rpm x86_64: 86936f627f02c8f96da5467c536997e6 perl-DBI-1.32-9.x86_64.rpm Red Hat Desktop version 3: SRPMS: ftp://updates.redhat.com/enterprise/3desktop/en/os/SRPMS/perl-DBI-1.32-9.src.rpm eabf3cd83dd61c9b09d2bb6e2160755a perl-DBI-1.32-9.src.rpm i386: 6aea6d47ab2a26300af6ed577405e6b7 perl-DBI-1.32-9.i386.rpm x86_64: 86936f627f02c8f96da5467c536997e6 perl-DBI-1.32-9.x86_64.rpm Red Hat Enterprise Linux ES version 3: SRPMS: ftp://updates.redhat.com/enterprise/3ES/en/os/SRPMS/perl-DBI-1.32-9.src.rpm eabf3cd83dd61c9b09d2bb6e2160755a perl-DBI-1.32-9.src.rpm i386: 6aea6d47ab2a26300af6ed577405e6b7 perl-DBI-1.32-9.i386.rpm ia64: 9f9dbb9313e84f86908b00aeb737c424 perl-DBI-1.32-9.ia64.rpm x86_64: 86936f627f02c8f96da5467c536997e6 perl-DBI-1.32-9.x86_64.rpm Red Hat Enterprise Linux WS version 3: SRPMS: ftp://updates.redhat.com/enterprise/3WS/en/os/SRPMS/perl-DBI-1.32-9.src.rpm eabf3cd83dd61c9b09d2bb6e2160755a perl-DBI-1.32-9.src.rpm i386: 6aea6d47ab2a26300af6ed577405e6b7 perl-DBI-1.32-9.i386.rpm ia64: 9f9dbb9313e84f86908b00aeb737c424 perl-DBI-1.32-9.ia64.rpm x86_64: 86936f627f02c8f96da5467c536997e6 perl-DBI-1.32-9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://www.redhat.com/security/team/key/#package 7. References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0077 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://www.redhat.com/security/team/contact/ ──────────────────────────────────────── -----BEGIN PGP SIGNATURE----- Version: PGP 7.0.4 iQEVAwUBQhRWBacyQYefg2/NAQHwWggAgUGeuLwgx2az6WKd68ieppAXrGrcG7gY R/xuQtOnFJHntKXoxjDTYFZoXSEH+GDXYwG1eYiZFoVKQAGQ9NSg/Q1dQ+Qo+7DT Mq7vmSuiUOvRVkod6rY8aTfsNfXotgx79/k4XB/urvlFrwtggb+8d+NkRLd6daB0 M16Q4Mm8OoJIrKynGcQRUW3e9qhk9UZWMqvXUU79l7OsqlyL7Hbf6VT7P6CADapy fbM8MzJc2zXD6lY44NKiqusShCHAsvYqddEMkJ0Y7ww8B8c7Eayqr+0J4XnEHNyq HDIOz2SIhv4/1Ecv3BqZJxq98In6/NYuQvJHehgr3doKpXTze7dKMQ== =6+8N -----END PGP SIGNATURE----- -- Taiwan Computer Emergency Response Team Security Advisory mailing list. Mail to : Majordomo@cert.org.tw and include a line "subscribe advisory". Please visit http://www.cert.org.tw/. PGP key : http://www.cert.org.tw/eng/pgp.htm
文章代碼(AID): #1255rL00 (NetSecurity)
文章代碼(AID): #1255rL00 (NetSecurity)