JVNDB-2016-007655
|
OpenSSL �ɕ����̐Ǝ㐫
|
OpenSSL �ɂ́A�����̐Ǝ㐫�����݂��܂��B
OpenSSL �́A���̕����̐Ǝ㐫���C�������A�b�v�f�[�g�������[�X���܂����B
�@�@* ciphersuite ChaCha20/Poly1305 �Ƀq�[�v�o�b�t�@�I�[�o�[�t���[ - CVE-2016-7054 (�d�v�x�F��)
�@�@* ������ CMS �\���̏����ɂ����� NULL �|�C���^�Q�Ƃ̖�� - CVE-2016-7053 (�d�v�x�F��)
�@�@* �����S������Z�����̌�� - CVE-2016-7055 (�d�v�x�F��)
|
|
|
OpenSSL Project
- OpenSSL 1.1.0c ���O�̃o�[�W���� (CVE-2016-7053, CVE-2016-7054, CVE-2016-7055)
- OpenSSL 1.0.2 (CVE-2016-7055)
���{�d�C
- EnterpriseDirectoryServer �S�o�[�W����
- EnterpriseIdentityManager 2.0�ȍ~
- ESMPRO/ServerAgent 4.4.22-1�ȍ~ (Linux��)
- ESMPRO/ServerAgentService �S�o�[�W���� (Linux��)
- SystemDirector Enterprise
- WebOTX Application Server Enterprise
- WebOTX Application Server Express
- WebOTX Application Server Foundation
- WebOTX Application Server Standard
- WebOTX Enterprise Service Bus
- WebOTX Portal
- Express5800 /SG �S�o�[�W����
����
- Cosminexus HTTP Server
- uCosminexus Application Server
- uCosminexus Application Server (64)
- uCosminexus Application Server -R
- uCosminexus Developer
- uCosminexus Primary Server Base
- uCosminexus Primary Server Base(64)
- uCosminexus Service Architect
- uCosminexus Service Platform
- uCosminexus Service Platform (64)
|
�{�Ǝ㐫�̉e�����鐻�i�̏ڍׂɂ��ẮA�x���_���юQ�l�������m�F���������B
|
�z�肳���e���͊e�Ǝ㐫�ɂ��قȂ�܂����A�A�v���P�[�V�������N���b�V������T�[�r�X�^�p�W�Q (DoS) �U������Ȃǂ̉\��������܂��B
|
[�A�b�v�f�[�g����]
�J���҂�����������ƂɁA�ŐV�łփA�b�v�f�[�g���ĉ������B
�{�Ǝ㐫���C������ OpenSSL 1.1.0c �������[�X����Ă��܂��B
�Ȃ��A CVE-2016-7055 �� �d�v�x�F�� �̂��߁A2016�N11��11�����݁ACVE-2016-7055 �ɑ��� OpenSSL 1.0.2 �̃A�b�v�f�[�g�̓����[�X����Ă��܂���B
|
OpenSSL Project
���{�d�C
����
|
|
- CVE-2016-7053
- CVE-2016-7054
- CVE-2016-7055
|
- JVN : JVNVU#92930223
- JVN : JVNVU#92830136
- National Vulnerability Database (NVD) : CVE-2016-7053
- National Vulnerability Database (NVD) : CVE-2016-7054
- National Vulnerability Database (NVD) : CVE-2016-7055
|
- [2017�N03��09��]
�f��
[2017�N06��29��]
�e������V�X�e���F�x���_���̒lj��ɔ������e���X�V
�x���_���F���� (hitachi-sec-2017-115) ��lj�
[2017�N07��25��]
�e������V�X�e���F�x���_���̒lj��ɔ������e���X�V
�x���_���F���{�d�C (NV17-011) ��lj�
�Q�l���FJVN (JVNVU#92830136) ��lj�
[2017�N10��03��]
�e������V�X�e���F�x���_��� (NV17-009) �̍X�V�ɔ������e���X�V
�e������V�X�e���F�x���_��� (NV17-011) �̍X�V�ɔ������e���X�V
[2018�N01��24��]
�Q�l���FNational Vulnerability Database (NVD) (CVE-2016-7053) ��lj�
�Q�l���FNational Vulnerability Database (NVD) (CVE-2016-7054) ��lj�
�Q�l���FNational Vulnerability Database (NVD) (CVE-2016-7055) ��lj�
[2018�N02��07��]
�e������V�X�e���F�x���_��� (NV17-009) �̍X�V�ɔ������e���X�V
�e������V�X�e���F�x���_��� (NV17-011) �̍X�V�ɔ������e���X�V
|