Debian セキュリティ勧告
DSA-224-1 canna -- バッファオーバフローほか
- 報告日時:
- 2003-01-08
- 影響を受けるパッケージ:
- canna
- 危険性:
- あり
- 参考セキュリティデータベース:
- (SecurityFocus の) Bugtraq データベース: BugTraq ID 6351, BugTraq ID 6354.
Mitre の CVE 辞書: CVE-2002-1158, CVE-2002-1159. - 詳細:
-
日本語入力システム canna に幾つかの脆弱性が発見されました。The Common Vulnerabilities and Exposures (CVE) プロジェクトでは以下の問題を確認しています。
- CAN-2002-1158 (BugTraq Id 6351): Shadow Penguin Security の "hsj" さんにより、canna サーバの irw_through 関数にヒープオーバフロー脆弱性が発見されました。
- CAN-2002-1159 (BugTraq Id 6354): Canna project の Shinra Aida さんにより、 canna がリクエストを適切に検証していないことが発見されました。 この問題により、リモートの攻撃者によりサービス不能攻撃や情報を 漏洩させることが可能になっています。
現安定版 (stable) (woody) では、これはバージョン 3.5b2-46.2 で修正されてい ます。
旧安定版 (potato) では、これはバージョン 3.5b2-25.2 で修正されています。
不安定版 (unstable) (sid) では、これはバージョン 3.6p1-1 で修正されています。
すぐに canna パッケージをアップグレードすることを勧めます。
- 修正:
-
Debian GNU/Linux 2.2 (potato)
- ソース:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2.dsc
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2.diff.gz
- http://ftp.debian.org/debian/dists/potato/main/source/utils/canna_3.5b2.orig.tar.gz
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2.diff.gz
- Alpha:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_alpha.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_alpha.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_alpha.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_alpha.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_alpha.deb
- ARM:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_arm.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_arm.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_arm.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_arm.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_arm.deb
- Intel IA-32:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_i386.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_i386.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_i386.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_i386.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_i386.deb
- Motorola 680x0:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_m68k.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_m68k.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_m68k.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_m68k.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_m68k.deb
- PowerPC:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_powerpc.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_powerpc.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_powerpc.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_powerpc.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_powerpc.deb
- Sun Sparc:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-25.2_sparc.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_sparc.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-25.2_sparc.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-25.2_sparc.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-25.2_sparc.deb
Debian GNU/Linux 3.0 (woody)
- ソース:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2.dsc
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2.diff.gz
- http://ftp.debian.org/debian/pool/main/c/canna/canna_3.5b2.orig.tar.gz
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2.diff.gz
- Alpha:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_alpha.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_alpha.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_alpha.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_alpha.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_alpha.deb
- ARM:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_arm.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_arm.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_arm.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_arm.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_arm.deb
- Intel IA-32:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_i386.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_i386.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_i386.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_i386.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_i386.deb
- Intel IA-64:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_ia64.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_ia64.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_ia64.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_ia64.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_ia64.deb
- HPPA:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_hppa.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_hppa.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_hppa.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_hppa.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_hppa.deb
- Motorola 680x0:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_m68k.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_m68k.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_m68k.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_m68k.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_m68k.deb
- Big endian MIPS:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_mips.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_mips.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_mips.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_mips.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_mips.deb
- Little endian MIPS:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_mipsel.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_mipsel.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_mipsel.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_mipsel.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_mipsel.deb
- PowerPC:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_powerpc.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_powerpc.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_powerpc.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_powerpc.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_powerpc.deb
- IBM S/390:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_s390.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_s390.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_s390.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_s390.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_s390.deb
- Sun Sparc:
- http://security.debian.org/pool/updates/main/c/canna/canna_3.5b2-46.2_sparc.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_sparc.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g_3.5b2-46.2_sparc.deb
- http://security.debian.org/pool/updates/main/c/canna/libcanna1g-dev_3.5b2-46.2_sparc.deb
- http://security.debian.org/pool/updates/main/c/canna/canna-utils_3.5b2-46.2_sparc.deb
一覧にあるファイルの MD5 チェックサムは勧告の原文にあります。