漏洞信息详情
Joshua Chamas Crypt::SSLeay Perl模块不安全信息熵源漏洞
漏洞简介
libnet-ssleay-perl的1.25之前版本中的SSLeay.pm如果在EGD_PATH变量中未设置源,使用/tmp/entropy文件为熵,本地用户可以通过修改此文件来减少某些操作的密码强度。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Joshua Chamas Crypt::SSLeay 1.25
Mandriva perl-Net_SSLeay-1.25-4.1.101mdk.i586.rpm
Mandriva Linux 10.1:
http://wwwnew.mandriva.com/en/downloads/
Mandriva perl-Net_SSLeay-1.25-4.1.101mdk.x86_64.rpm
Mandriva Linux 10.1:
http://wwwnew.mandriva.com/en/downloads/
Mandriva perl-Net_SSLeay-1.25-4.1.102mdk.i586.rpm
Mandriva Linux 10.2:
http://wwwnew.mandriva.com/en/downloads/
Mandriva perl-Net_SSLeay-1.25-4.1.102mdk.x86_64.rpm
Mandriva Linux 10.2:
http://wwwnew.mandriva.com/en/downloads/
Mandriva perl-Net_SSLeay-1.25-4.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/
Mandriva perl-Net_SSLeay-1.25-4.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/
Mandriva perl-Net_SSLeay-1.25-4.1.C30mdk.i586.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/
Mandriva perl-Net_SSLeay-1.25-4.1.C30mdk.x86_64.rpm
Corporate 3.0:
http://wwwnew.mandriva.com/en/downloads/
Joshua Chamas Crypt::SSLeay 0.51
Ubuntu libnet-ssleay-perl_1.25-1ubuntu0.2_amd64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/libn/libnet-ssleay-perl/li bnet-ssleay-perl_1.25-1ubuntu0.2_amd64.deb
Ubuntu libnet-ssleay-perl_1.25-1ubuntu0.2_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/libn/libnet-ssleay-perl/li bnet-ssleay-perl_1.25-1ubuntu0.2_i386.deb
Ubuntu libnet-ssleay-perl_1.25-1ubuntu0.2_powerpc.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/libn/libnet-ssleay-perl/li bnet-ssleay-perl_1.25-1ubuntu0.2_powerpc.deb
参考网址
来源: UBUNTU
名称: USN-113-1
链接:http://www.ubuntulinux.org/support/documentation/usn/usn-113-1
来源: BID
名称: 13471
链接:http://www.securityfocus.com/bid/13471
来源: MANDRIVA
名称: MDKSA-2006:023
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:023
来源: SECUNIA
名称: 18639
链接:http://secunia.com/advisories/18639
受影响实体
- Ubuntu Ubuntu_linux:5.04<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...