From owner-doc-jp-work@jp.FreeBSD.org Fri Aug  2 16:03:39 2002
Received: (from daemon@localhost)
	by castle.jp.FreeBSD.org (8.11.6+3.4W/8.11.3) id g7273dH21144;
	Fri, 2 Aug 2002 16:03:39 +0900 (JST)
	(envelope-from owner-doc-jp-work@jp.FreeBSD.org)
Received: from smtp.eos.ocn.ne.jp (eos.ocn.ne.jp [211.6.83.117])
	by castle.jp.FreeBSD.org (8.11.6+3.4W/8.11.3) with ESMTP/inet id g7273bn21138
	for <doc-jp-work@jp.FreeBSD.org>; Fri, 2 Aug 2002 16:03:37 +0900 (JST)
	(envelope-from hrs@eos.ocn.ne.jp)
Received: from mail.allbsd.org (p8065-adsah09hon-acca.tokyo.ocn.ne.jp [218.224.7.65])
	by smtp.eos.ocn.ne.jp (Postfix) with ESMTP id 3A01D1360
	for <doc-jp-work@jp.FreeBSD.org>; Fri,  2 Aug 2002 16:03:35 +0900 (JST)
Received: from localhost (alph.allbsd.org [192.168.0.10])
	by mail.allbsd.org (8.12.3/3.7W/DomainMaster) with ESMTP id g726nXLu070935
	for <doc-jp-work@jp.FreeBSD.org>; Fri, 2 Aug 2002 15:49:34 +0900 (JST)
	(envelope-from hrs@eos.ocn.ne.jp)
Date: Fri, 02 Aug 2002 15:46:57 +0900 (JST)
Message-Id: <20020802.154657.102844913.hrs@eos.ocn.ne.jp>
To: doc-jp-work@jp.FreeBSD.org
From: Hiroki Sato <hrs@eos.ocn.ne.jp>
In-Reply-To: <20020802.124212.130143986.y-koga@jp.FreeBSD.org>
	<20020802.063756.112281608.rushani@bl.mmtr.or.jp>
References: <20020802.063756.112281608.rushani@bl.mmtr.or.jp>
	<20020802.124212.130143986.y-koga@jp.FreeBSD.org>
X-Mailer: Mew version 2.2 on Emacs 20.7 / Mule 4.0 (HANANOEN)
Mime-Version: 1.0
Content-Type: Text/Plain; charset=iso-2022-jp
Content-Transfer-Encoding: 7bit
Reply-To: doc-jp-work@jp.FreeBSD.org
Precedence: list
X-Sequence: doc-jp-work 449
Subject: [doc-jp-work 449] Re: ANNOUNCE: FreeBSD Security Advisory
 FreeBSD-SA-02:33.openssl
Errors-To: owner-doc-jp-work@jp.FreeBSD.org
Sender: owner-doc-jp-work@jp.FreeBSD.org
X-Originator: hrs@eos.ocn.ne.jp
X-Distribute: distribute version 2.1 (Alpha) patchlevel 24e+020727

$B:4F#!wEl5~M}2JBg3X$G$9!#(B

 8355 $B$N(B mail2sa.pl $B$O$A$g$C$H8E$$$N$G!":G6a$N(B SA $B$@$H(B
 $B$&$^$/=hM}$G$-$J$+$C$?$j$7$^$9!#(B

 http://home.jp.FreeBSD.org/%7Ehrs/doc-jp/mail2sa.pl

 $B$KCV$$$F$"$j$^$9$N$G!"?7$7$$$N$r$R$C$Q$C$F$/$@$5$$$J!#(B

Hideyuki KURASHINA <rushani@bl.mmtr.or.jp> wrote
  in <20020802.063756.112281608.rushani@bl.mmtr.or.jp>:

rushani> FreeBSD includes software from the OpenSSL Project.  The
rushani> OpenSSL Project is a collaborative effort to develop a robust,
rushani> commercial-grade, full-featured, and Open Source toolkit implementing
rushani> the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS
rushani> v1) protocols as well as a full-strength general purpose cryptography
rushani> library.
rushani> FreeBSD $B$O(B OpenSSL Project $BM3Mh$N%=%U%H%&%'%"$r:NMQ$7$F$$$^$9!#(B
rushani> OpenSSL Project $B$O6/NO$JHFMQL\E*$N0E9f%i%$%V%i%j$H$H$b$K(B
rushani> Secure Sockets Layer (SSL v2/v3) $B$H(B Transport Layer Security (TLS v1)
rushani> $B%W%m%H%3%k$r<BAu$7$?!"7xO4$G!">&MQIJ<A$N!"5!G=K-IY$J%*!<%W%s%=!<%9(B
rushani> $B%D!<%k%-%C%H$r3+H/$KNO$rCm$$$G$$$^$9!#(B

 $B$3$3$O(B 01:52 $B$+$i(B cut&paste $B$C$]$$!#(B

 hrs> FreeBSD $B$K$O(B, OpenSSL $B%W%m%8%'%/%H$K$h$k%=%U%H%&%'%"$,4^$^$l$F$$$^$9(B.
 hrs> OpenSSL $B%W%m%8%'%/%H$O(B, Secure Sockets Layer (SSL v2/v3) $B$*$h$S(B
 hrs> Transport Layer Security (TLS v1) $B$K2C$((B, $BI}9-$$0E9f6/EY$KBP1~$7$?(B
 hrs> $BHFMQ$N0E9f%i%$%V%i%j$r<BAu$9$k$?$a$N(B, $B6/8G$G>&IJ$H$7$FDLMQ$9$kIJ<A$r;}$A(B,
 hrs> $B==J,$J5!G=$rHw$($?%*!<%W%s%=!<%9$N%D!<%k%-%C%H$N3+H/$r6(NO$7$F9T$J$C$F$$$k(B
 hrs> $B%W%m%8%'%/%H$G$9(B.

rushani> The OpenSSL libraries contain multiple buffer overflows, including
rushani> errors in the handling of the client master key in the SSL2 protocol
rushani> implementation; the handling of the session ID in the SSL3 protocol;
rushani> and in the handling of buffers used for representing integers in
rushani> ASCII on 64-bit platforms.  In addition, arbitrary or intentionally
rushani> malicious data passed to the ASN.1 decoder may cause undefined
rushani> behavior.
rushani> OpenSSL $B$N%i%$%V%i%j$OJ#?t$N%P%C%U%!%*!<%P%U%m!<$r4^$s$G$$$^$9!#(B
rushani> $B6qBNE*$K$O(B SSL2 $B%W%m%H%3%k$N<BAu$K$*$1$k%/%i%$%"%s%H$N%^%9%?!<%-!<$N(B
rushani> $B<h07$$$K4X$9$k%(%i!<!"(BSSL3 $B%W%m%H%3%k$N<BAu$K$*$1$k%;%C%7%g%s(B ID $B$N(B
rushani> $B<h07$$$K4X$9$k%(%i!<!"(B64-bit $B%W%i%C%H%U%)!<%`>e$K$*$$$F$N(B ASCII $B$r(B
rushani> $B@0?t$rI=8=$9$k$N$KMQ$$$i$l$k%P%C%U%!$N<h07$$%(%i!<$G$9!#$5$i$K!"(B
rushani> ASN.1 $B%G%3!<%@$rDL2a$7$?!"G$0U$N$"$k$$$O8N0U$N0-0U$"$k%G!<%?$K$h$C$F(B
rushani> $BL$Dj5A$N5sF0$r<($92DG=@-$,$"$j$^$9!#(B

 $B!V%(%i!<!W$O$A$g$C$HJ,$+$j$K$/$$$+$b!#(B

 hrs> OpenSSL $B$N%i%$%V%i%j$K$O!"(BSSL2 $B%W%m%H%3%k<BAu$N(B
 hrs> $B%/%i%$%"%s%H%^%9%?%-!<$N=hM}!"(BSSL3 $B%W%m%H%3%k<BAu$N(B
 hrs> $B%;%7%g%s(B ID $B$N=hM}!"(B64-bit $B%W%i%C%H%U%)!<%`$K(B
 hrs> $B$*$$$F@0?t$N(B ASCII $BI=8=$K;H$o$l$F$$$k%P%C%U%!$N=hM}$J$I$K!"(B
 hrs> $B%P%C%U%!%*!<%P%U%m!<$r0z$-5/$3$98m$j$,J#?t4^$^$l$F$$$^$9!#(B

 $B$3$3$N(B arbitrary $B$rG$0U$H$9$k$H(B any $B$N0UL#$KFI$a$F(B
 $B0UL#ITL@$K$J$k$N$G!"JLI=8=$r$H$C$?J}$,$h$$$G$7$g$&!#(B 

  # $B86J8$,0-$$!#(B

 hrs> $B$^$?!"$"$kFCDj$N%G!<%?$,(B ASN.1 $B%G%3!<%@$KM?$($i$l$k$H!"(B
 hrs> $BL$Dj5A$NF0:n$r0z$-5/$3$9$H$$$&LdBj$,$"$j$^$9!#(B
 hrs> $B$3$N%G!<%?$O!"0-0U$r;}$C$F0U?^E*$K:n@.$9$k$3$H$b2DG=$G$9!#(B

rushani> At least one of the buffer overflows is known to be exploitable, and
rushani> the others may be as well.  A successful exploit of an application
rushani> using OpenSSL may result in arbitrary code execution.  Both clients
rushani> and servers may be attacked.
rushani> $B>/$J$/$H$b%P%C%U%!%*!<%P%U%m!<$N$R$H$D$r0-MQ$7$F967b2DG=$JJ}K!$,(B
rushani> $BCN$i$l$F$*$j!"B>$N<jK!$b$^$?F1MM$@$H;W$o$l$^$9!#(BOpenSSL $B$rMxMQ$7$?(B
rushani> $B%"%W%j%1!<%7%g%s$X$N967b$,@.8y$7$F$7$^$&$H!"967b<T$,G$0U$N%3!<%I$r(B
rushani> $B<B9T$7$F$7$^$&2DG=@-$,$"$j$^$9!#$^$?!"%5!<%P$H%/%i%$%"%s%H$NN>J}$H$b$,(B
rushani> $B967b$r<u$1$kBP>]$K$J$j$($^$9!#(B

 hrs> $B$3$N967b$O!"%/%i%$%"%s%H$H%5!<%P$NN>J}$KBP$7$F9T$J$&$3$H$,2DG=$G$9!#(B

rushani> Note that any statically linked applications that are not part of
rushani> the base system (i.e. from the Ports Collection or other 3rd-party
rushani> sources) must be recompiled if they use OpenSSL (libssl or libcrypto).
rushani> $B%Y!<%9%7%9%F%`$N9=@.J*$K4^$^$l$J$$!"@EE*$K%j%s%/$5$l$?%"%W%j%1!<%7%g%s(B
rushani> ($B$9$J$o$A(B Ports Collection $B$+$i%S%k%I$7$?$b$N$d!"%5!<%I%Q!<%F%#$N(B
rushani> $B%=!<%9(B) $B$O(B OpenSSL (libssl $B$^$?$O(B libcrypto) $B$rMxMQ$7$F$$$k$J$i$P!"(B
rushani> $B:F%3%s%Q%$%k$7$J$1$l$P$J$i$J$$$H$$$&$3$H$KCm0U$7$F$/$@$5$$!#(B

 hrs> $B$^$?!"(BOpenSSL (libssl $B$^$?$O(B libcrypto) $B$rMxMQ$7$F@EE*$K(B
 hrs> $B%j%s%/$5$l$?%"%W%j%1!<%7%g%s$G!"%Y!<%9%7%9%F%`$K4^$^$l$F$$$J$$$b$N(B
 hrs> ($B$D$^$j(B Ports Collection $B$d%5!<%I%Q!<%F%#@=$N%=!<%9$+$i%3%s%Q%$%k$7$?$b$N(B)
 hrs> $B$b!"$9$Y$F:F%3%s%Q%$%k$9$kI,MW$,$"$k$3$H$KCm0U$7$F$/$@$5$$!#(B

rushani> The following components of the FreeBSD base system are known to
rushani> utilize OpenSSL's libssl or libcrypto.  System administrators may
rushani> choose to recompile only these applications rather than the entire
rushani> operating system, though it is not recommended.
rushani> FreeBSD $B$K4^$^$l$k0J2<$N%3%s%]!<%M%s%H$O!"(BOpenSSL $B$N(B libssl $B$^$?$O(B
rushani> libcrypto $B$rMxMQ$7$F$$$k$3$H$,CN$i$l$F$$$^$9!#%7%9%F%`$N4IM}<T$O(B
rushani> $B%*%Z%l!<%F%#%s%0%7%9%F%`A4BN$r:F%3%s%Q%$%k$9$k$h$j$b!"$3$l$i$N(B
rushani> $B%"%W%j%1!<%7%g%s$N$_$r:F%3%s%Q%$%k$9$k$3$H$b2DG=$G$9(B ($B$*>)$a$7$^$;$s(B)$B!#(B

 $B8D?ME*$K$O(B be known to $B$r!VCN$i$l$F$$$k!W$H$9$k$H(B
 $B$R$H$4$H$C$]$/J9$3$($k$N$G!"!VH=L@$7$F$$$k!W$H$+(B
 $B!V3NG'$5$l$F$$$k!W$H$9$kJ}$,9%$_$G$9!#(B

Koga Youichirou <y-koga@jp.FreeBSD.org> wrote
  in <20020802.124212.130143986.y-koga@jp.FreeBSD.org>:

y-koga> > $hrs$
y-koga> 
y-koga> ?

 mail2sa.pl $B$N(B $translator $B$H(B $rcsid $B$OE,Ev$KJQ99$7$^$7$g$&(B :-)

--
| $B:4F#(B $B9-@8!wEl5~M}2JBg3X(B <hrs@eos.ocn.ne.jp>
|                         <hrs@FreeBSD.org> (FreeBSD Project)
