From owner-doc-jp-work@jp.FreeBSD.org Fri Aug  2 12:42:39 2002
Received: (from daemon@localhost)
	by castle.jp.FreeBSD.org (8.11.6+3.4W/8.11.3) id g723gdu76001;
	Fri, 2 Aug 2002 12:42:39 +0900 (JST)
	(envelope-from owner-doc-jp-work@jp.FreeBSD.org)
Received: from TYO202.gate.nec.co.jp (TYO202.gate.nec.co.jp [210.143.35.52])
	by castle.jp.FreeBSD.org (8.11.6+3.4W/8.11.3) with ESMTP/inet id g723gZn75994;
	Fri, 2 Aug 2002 12:42:35 +0900 (JST)
	(envelope-from y-koga@jp.FreeBSD.org)
Received: from mailgate4.nec.co.jp ([10.7.69.195])
	by TYO202.gate.nec.co.jp (8.11.6/3.7W01080315) with ESMTP id g723gDL23391;
	Fri, 2 Aug 2002 12:42:13 +0900 (JST)
Received: from mailsv4.nec.co.jp (mailgate51.nec.co.jp [10.7.69.190]) by mailgate4.nec.co.jp (8.11.6/3.7W-MAILGATE-NEC) with ESMTP
	id g723gCX22061; Fri, 2 Aug 2002 12:42:12 +0900 (JST)
Received: from necspl.do.mms.mt.nec.co.jp (necspl.do.mms.mt.nec.co.jp [10.16.5.21]) by mailsv4.nec.co.jp (8.11.6/3.7W-MAILSV4-NEC) with ESMTP
	id g723gCG10810; Fri, 2 Aug 2002 12:42:12 +0900 (JST)
Received: from localhost (localhost [IPv6:::1])
	by  necspl.do.mms.mt.nec.co.jp (8.12.5/8.12.5) with ESMTP id g723gC3A022480;
	Fri, 2 Aug 2002 12:42:12 +0900 (JST)
Date: Fri, 02 Aug 2002 12:42:12 +0900 (JST)
Message-Id: <20020802.124212.130143986.y-koga@jp.FreeBSD.org>
To: doc-jp-work@jp.FreeBSD.org
From: Koga Youichirou <y-koga@jp.FreeBSD.org>
In-Reply-To: <20020802.063756.112281608.rushani@bl.mmtr.or.jp>
References: <20020802.063756.112281608.rushani@bl.mmtr.or.jp>
X-Mailer: Mew version 3.0.60 on Emacs 21.2 / Mule 5.0 (SAKAKI)
Mime-Version: 1.0
Content-Type: Text/Plain; charset=iso-2022-jp
Content-Transfer-Encoding: 7bit
Reply-To: doc-jp-work@jp.FreeBSD.org
Precedence: list
X-Sequence: doc-jp-work 448
Subject: [doc-jp-work 448] Re: ANNOUNCE: FreeBSD Security Advisory
 FreeBSD-SA-02:33.openssl
Errors-To: owner-doc-jp-work@jp.FreeBSD.org
Sender: owner-doc-jp-work@jp.FreeBSD.org
X-Originator: y-koga@jp.FreeBSD.org
X-Distribute: distribute version 2.1 (Alpha) patchlevel 24e+020727

Hideyuki KURASHINA <rushani@bl.mmtr.or.jp>:
> 02:33 $B$G$9(B. $B::FI$r$*4j$$$7$^$9(B.

$B$Q$A$Q$A$Q$A!y(B

> FreeBSD $B%;%-%e%j%F%#4+9p(B $BF|K\8lHG(B
> =============================================================================
>  (2002-07-31)
>  * openssl contains multiple vulnerabilities
> =============================================================================
- snip -
>                                      [$BK]Lu<T(B: $B:4F#(B $B9-@8(B <hrs@jp.FreeBSD.org>]

$BB?J,!":4F#$5$s$8$c$J$$$H;W$$$^$9(B :)

> =============================================================================
> FreeBSD-SA-02:33.openssl                                    Security Advisory
- snip -
> 
> $B%H%T%C%/(B:	openssl $B$K$*$1$kJ#?t$N%;%-%e%j%F%#>e$N<eE@(B

$B:Y$+$$OC$G$9$,!"86J8$G$O(B TAB $B$r;H$C$F$J$$$h$&$G$9!#0J9_$bF1MM!#(B

> I.   $BGX7J(B - Background
> 
> FreeBSD includes software from the OpenSSL Project.  The
> OpenSSL Project is a collaborative effort to develop a robust,
> commercial-grade, full-featured, and Open Source toolkit implementing
> the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS
> v1) protocols as well as a full-strength general purpose cryptography
> library.
> FreeBSD $B$O(B OpenSSL Project $BM3Mh$N%=%U%H%&%'%"$r:NMQ$7$F$$$^$9!#(B
> OpenSSL Project $B$O6/NO$JHFMQL\E*$N0E9f%i%$%V%i%j$H$H$b$K(B
> Secure Sockets Layer (SSL v2/v3) $B$H(B Transport Layer Security (TLS v1)
> $B%W%m%H%3%k$r<BAu$7$?!"7xO4$G!">&MQIJ<A$N!"5!G=K-IY$J%*!<%W%s%=!<%9(B
> $B%D!<%k%-%C%H$r3+H/$KNO$rCm$$$G$$$^$9!#(B

full-featured $B$N(B full- $B$O!VK-IY!W$H$$$&$h$j!V==J,!W$G$O$J$$$+$H!#(B
full-strength $B$bF1MM!#(B

> $B%D!<%k%-%C%H$r3+H/$KNO$rCm$$$G$$$^$9!#(B

$B%D!<%k%-%C%H$N3+H/$K!D(B
$B$^$?$O(B
$B%D!<%k%-%C%H$r3+H/$9$k$3$H$K!D(B

> II.  $BLdBj$N>\:Y(B - Problem Description
> 
> The OpenSSL libraries contain multiple buffer overflows, including
> errors in the handling of the client master key in the SSL2 protocol
> implementation; the handling of the session ID in the SSL3 protocol;
> and in the handling of buffers used for representing integers in
> ASCII on 64-bit platforms.  In addition, arbitrary or intentionally
> malicious data passed to the ASN.1 decoder may cause undefined
> behavior.
> OpenSSL $B$N%i%$%V%i%j$OJ#?t$N%P%C%U%!%*!<%P%U%m!<$r4^$s$G$$$^$9!#(B
> $B6qBNE*$K$O(B SSL2 $B%W%m%H%3%k$N<BAu$K$*$1$k%/%i%$%"%s%H$N%^%9%?!<%-!<$N(B
> $B<h07$$$K4X$9$k%(%i!<!"(BSSL3 $B%W%m%H%3%k$N<BAu$K$*$1$k%;%C%7%g%s(B ID $B$N(B
> $B<h07$$$K4X$9$k%(%i!<!"(B64-bit $B%W%i%C%H%U%)!<%`>e$K$*$$$F$N(B ASCII $B$r(B
> $B@0?t$rI=8=$9$k$N$KMQ$$$i$l$k%P%C%U%!$N<h07$$%(%i!<$G$9!#$5$i$K!"(B
> ASN.1 $B%G%3!<%@$rDL2a$7$?!"G$0U$N$"$k$$$O8N0U$N0-0U$"$k%G!<%?$K$h$C$F(B
> $BL$Dj5A$N5sF0$r<($92DG=@-$,$"$j$^$9!#(B

s/$B<h07$$(B/$B<h$j07$$(B/ ($B!VD+F|?7J9$NMQ8l$N<j0z!W(B)
$B!V=hM}!W$G$b$$$$$+$J!#(B

64-bit $B%W%i%C%H%U%)!<%`>e$K$*$$$F$N(B ASCII $B$r@0?t$rI=8=$9$k$N$KMQ$$$i$l(B
$B$k%P%C%U%!$N<h07$$%(%i!<$G$9(B
$B"*(B
$B@0?t$r(B ASCII $B$GI=8=$9$k$N$KMQ$$$k%P%C%U%!$N(B 64-bit $B%W%i%C%H%U%)!<%`$K(B
$B$*$1$k<h$j07$$%(%i!<$G$9(B

$B$"$H!"8D?ME*$K$O(B
s/$B%^%9%?!<(B/$B%^%9%?(B/

> III. $B1F6AHO0O(B - Impact
> 
> At least one of the buffer overflows is known to be exploitable, and
> the others may be as well.  A successful exploit of an application
> using OpenSSL may result in arbitrary code execution.  Both clients
> and servers may be attacked.
> $B>/$J$/$H$b%P%C%U%!%*!<%P%U%m!<$N$R$H$D$r0-MQ$7$F967b2DG=$JJ}K!$,(B
> $BCN$i$l$F$*$j!"B>$N<jK!$b$^$?F1MM$@$H;W$o$l$^$9!#(BOpenSSL $B$rMxMQ$7$?(B
> $B%"%W%j%1!<%7%g%s$X$N967b$,@.8y$7$F$7$^$&$H!"967b<T$,G$0U$N%3!<%I$r(B
> $B<B9T$7$F$7$^$&2DG=@-$,$"$j$^$9!#$^$?!"%5!<%P$H%/%i%$%"%s%H$NN>J}$H$b$,(B
> $B967b$r<u$1$kBP>]$K$J$j$($^$9!#(B

$BJ#?t$"$k%P%C%U%!%*!<%P%U%m!<$NFb$N>/$J$/$H$b0l$D$O0-MQ2DG=$G$"$k$3$H$,(B
$BCN$i$l$F$$$^$9!#$=$7$F!"$=$NB>$K$D$$$F$bF1MM$G$"$k2DG=@-$,$"$j$^$9!#(B

s/$B$^$?!"(B//
s/$B$J$j$($^$9(B/$B$J$jF@$^$9(B/

> IV.  $B2sHrJ}K!(B - Workaround
> 
> Disabling the SSL2 protocol in server applications should render
> server exploits harmless.  There is no known workaround for client
> applications.
> $B%5!<%P%"%W%j%1!<%7%g%s$N(B SSL2 $B%W%m%H%3%k$rL58z2=$9$k!#$3$l$O%5!<%P$K(B
> $BBP$9$k967b$r$J$/$7$^$9!#%/%i%$%"%s%H%"%W%j%1!<%7%g%s$KBP$9$kM-8z$J(B
> $B2sHrJ}K!$O$J$$$3$H$,CN$i$l$F$$$^$9!#(B

s/$B%5!<%P%"%W%j%1!<%7%g%s$N(B/$B%5!<%P%"%W%j%1!<%7%g%s$K$*$$$F(B/
s/$BL58z2=$9$k!#$3$l$O(B/$BL58z2=$9$k$3$H$G!"(B/
s/$B%5!<%P$KBP$9$k967b$r$J$/$7$^$9(B/$B%5!<%P$,96N,$5$l$F$7$^$&4m81@-$,$J$/$J$j$^$9(B/

> V.   $B2r7h:v(B - Solution
- snip -
> 1) Upgrade your vulnerable system to 4.6-STABLE; or to the RELENG_4_6,
> RELENG_4_5, or RELENG_4_4 security branch dated after the correction
> date (4.6.1-RELEASE-p3, 4.5-RELEASE-p13, or 4.4-RELEASE-p20).
> 1) $B<eE@$r;}$C$?(B FreeBSD $B%7%9%F%`$r=$@5F|0J9_$N(B 4.6-STABLE$B!"$b$7$/$O(B
>    RELENG_4_6$B!"(BRELENG_4_5$B!"(BRELENG_4_4 $B%;%-%e%j%F%#%V%i%s%A$N$$$:$l$+(B
>    (4.6.1-RELEASE-p3, 4.5-RELEASE-p13, or 4.4-RELEASE-p20) $B$K(B
>    $B%"%C%W%0%l!<%I$9$k!#(B

$B$3$l$O!"(B

$B<eE@$N$"$k%7%9%F%`$r!"(B($B:G?7$N(B) 4.6-STABLE $B$K(B upgrade $B$9$k$+!"=$@5F|(B
$B0J9_$N(B RELENG_4_6$B!"(BRELENG_4_5$B!"(BRELENG_4_4 $B$N%;%-%e%j%F%#%V%i%s%A$K(B
upgrade $B$9$k!#(B

$B$J$s$@$H;W$$$^$9!#(B

> 2) To patch your present system:
> 2) $B8=:_$N%7%9%F%`$K%Q%C%A$rE,MQ$9$k$K$O(B:

s/$B$9$k$K$O(B:/$B$9$k!#(B/

> The following patch has been verified to apply to FreeBSD 4.4, 4.5,
> and 4.6 systems.
> $B0J2<$N=$@5%Q%C%A$O!"(BFreeBSD 4.6$B!"(B4.5$B!"(B4.4-RELEASE $B$KE,MQ$G$-$k$3$H$,(B
> $B3NG'$5$l$F$$$k$b$N$G$9!#(B

-RELEASE $B$O$I$3$+$i=P$F$-$?$N$G$7$g$&(B?
$B2>$K(B -RELEASE $B$H$7$?$i!"(B4.6-RELEASE$B!"(B4.5-RELEASE$B!"(B4.4-RELEASE $B$H$7$F!"(B
$BN,$5$J$$J}$,$h$$$H;W$$$^$9!#(B

> b) Execute the following commands as root:
> b) root $B$G0J2<$N%3%^%s%I$r<B9T$7$^$9(B:

s/:/$B!#(B/

> c) Recompile the operating system as described in
> <URL:http://www.freebsd.org/doc/handbook/makeworld.html>.
> c) $B0J2<$K5-=R$5$l$F$$$k$h$&$K!"%*%Z%l!<%F%#%s%0%7%9%F%`$r(B
>    $B:F%3%s%Q%$%k$7$^$9!#(B
> <URL:http://www.freebsd.org/doc/handbook/makeworld.html>.

s/$B0J2<$K(B/$B0J2<$N%Z!<%8$K(B/
$B$NJ}$,$$$$$+$b!#(B

> Note that any statically linked applications that are not part of
> the base system (i.e. from the Ports Collection or other 3rd-party
> sources) must be recompiled if they use OpenSSL (libssl or libcrypto).
> $B%Y!<%9%7%9%F%`$N9=@.J*$K4^$^$l$J$$!"@EE*$K%j%s%/$5$l$?%"%W%j%1!<%7%g%s(B
> ($B$9$J$o$A(B Ports Collection $B$+$i%S%k%I$7$?$b$N$d!"%5!<%I%Q!<%F%#$N(B
> $B%=!<%9(B) $B$O(B OpenSSL (libssl $B$^$?$O(B libcrypto) $B$rMxMQ$7$F$$$k$J$i$P!"(B
> $B:F%3%s%Q%$%k$7$J$1$l$P$J$i$J$$$H$$$&$3$H$KCm0U$7$F$/$@$5$$!#(B

s/$B$9$J$o$A(B //

> All affected applications must be restarted in order to use the
> corrected library.  Though it is not required, rebooting may be the
> easiest way to accomplish this.
> $B1F6A$r<u$1$k$9$Y$F$N%"%W%j%1!<%7%g%s$O!"=$@5$5$l$?%i%$%V%i%j$r(B
> $B8z2L$r$($k$?$a$K:F5/F0$7$J$1$l$P$J$j$^$;$s!#$3$l$r9T$&$K$O!"%7%9%F%`$r(B
> $B:F5/F0$9$k$3$H$,$*$=$i$/:G$b4JC1$JJ}K!$G$7$g$&(B ($BI,?\$G$O$"$j$^$;$s(B)$B!#(B

$B=$@5$5$l$?%i%$%V%i%j$r8z2L$r$($k$?$a$K(B
$B"*=$@5$5$l$?%i%$%V%i%j$rM-8z$K$9$k$?$a$K(B

> The following components of the FreeBSD base system are known to
> utilize OpenSSL's libssl or libcrypto.  System administrators may
> choose to recompile only these applications rather than the entire
> operating system, though it is not recommended.
> FreeBSD $B$K4^$^$l$k0J2<$N%3%s%]!<%M%s%H$O!"(BOpenSSL $B$N(B libssl $B$^$?$O(B
> libcrypto $B$rMxMQ$7$F$$$k$3$H$,CN$i$l$F$$$^$9!#%7%9%F%`$N4IM}<T$O(B
> $B%*%Z%l!<%F%#%s%0%7%9%F%`A4BN$r:F%3%s%Q%$%k$9$k$h$j$b!"$3$l$i$N(B
> $B%"%W%j%1!<%7%g%s$N$_$r:F%3%s%Q%$%k$9$k$3$H$b2DG=$G$9(B ($B$*>)$a$7$^$;$s(B)$B!#(B

FreeBSD $B$K4^$^$l$k(B
$B"*(BFreeBSD $B$N%Y!<%9%7%9%F%`$K4^$^$l$k(B

$B:F%3%s%Q%$%k$9$k$h$j$b(B
$B"*:F%3%s%Q%$%k$;$:$K(B

> VI.  $B=$@5$N>\:Y(B - Correction details
> 
> The following list contains the revision numbers of each file that was
> corrected in FreeBSD.
> 
> $B<!$NI=$O!":#2s=$@5$5$l$?(B FreeBSD $B$K4^$^$l$k3F%U%!%$%k$N%j%S%8%g%sHV9f$G$9!#(B

FreeBSD $B$K$*$$$F:#2s=$@5$5$l$?3F%U%!%$%k$N%j%S%8%g%sHV9f$r0J2<$K<($7$^$9!#(B

> $hrs$

?
----
$B$3$,$h$&$$$A$m$&(B
