多嘴人 發表於 2021-11-5 09:56:00

银河麒麟V10系统openssh漏洞修复

<p><img src="https://img2020.cnblogs.com/blog/2565158/202111/2565158-20211105095126371-990624969.png"></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>https://www.kylinos.cn/support/loophole/343.html银河麒麟系统官网</p>
<p><img src="https://img2020.cnblogs.com/blog/2565158/202111/2565158-20211105095402891-485707427.png"></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div class="cnblogs_code">
<pre><span style="color: rgba(128, 0, 128, 1)">1</span><span style="color: rgba(0, 0, 0, 1)">. 修复的CVE信息:

CVE</span>-<span style="color: rgba(128, 0, 128, 1)">2018</span>-<span style="color: rgba(128, 0, 128, 1)">15919</span><span style="color: rgba(0, 0, 0, 1)">

描述:OpenSSH(OpenBSD Secure Shell)是OpenBSD计划组的一套用于安全访问远程计算机的连接工具。该工具是SSH协议的开源实现,支持对所有的传输进行加密,可有效阻止窃听、连接劫持以及其他网络级的攻击。OpenSSH </span><span style="color: rgba(128, 0, 128, 1)">7</span>.8及之前版本中的auth-<span style="color: rgba(0, 0, 0, 1)">gss2.c文件存在信息泄露漏洞。该漏洞源于网络系统或产品在运行过程中存在配置等错误。未授权的攻击者可利用漏洞获取受影响组件敏感信息。

CVE</span>-<span style="color: rgba(128, 0, 128, 1)">2020</span>-<span style="color: rgba(128, 0, 128, 1)">12062</span><span style="color: rgba(0, 0, 0, 1)">

描述:OpenSSH(OpenBSD Secure Shell)是OpenBSD计划组的一套用于安全访问远程计算机的连接工具。该工具是SSH协议的开源实现,支持对所有的传输进行加密,可有效阻止窃听、连接劫持以及其他网络级的攻击。OpenSSH </span><span style="color: rgba(128, 0, 128, 1)">8</span><span style="color: rgba(0, 0, 0, 1)">.2版本中存在安全漏洞,该漏洞源于在utimes系统调用失败时,scp客户端错误地向服务器发送了重复的响应。攻击者可通过在远程服务器上创建子目录利用该漏洞覆盖客户端下载目录中的任意文件。



</span><span style="color: rgba(128, 0, 128, 1)">2</span><span style="color: rgba(0, 0, 0, 1)">. 受影响的操作系统:

银河麒麟高级服务器操作系统V10(SP1)



</span><span style="color: rgba(128, 0, 128, 1)">3</span><span style="color: rgba(0, 0, 0, 1)">. 修复版本

银河麒麟高级服务器操作系统V10(SP1):openssh</span>-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10



</span><span style="color: rgba(128, 0, 128, 1)">4</span><span style="color: rgba(0, 0, 0, 1)">. 受影响的软件包

银河麒麟高级服务器操作系统V10(SP1)

x86_64:

openssh</span>-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.x86_64.rpm

openssh</span>-askpass-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.x86_64.rpm

openssh</span>-cavs-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.x86_64.rpm

openssh</span>-clients-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.x86_64.rpm

openssh</span>-keycat-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.x86_64.rpm

openssh</span>-ldap-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.x86_64.rpm

openssh</span>-server-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.x86_64.rpm

pam_ssh_agent_auth</span>-<span style="color: rgba(128, 0, 128, 1)">0.10</span>.<span style="color: rgba(128, 0, 128, 1)">3</span>-<span style="color: rgba(128, 0, 128, 1)">9.9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.x86_64.rpm

aarch64:

openssh</span>-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span>.p02.ky10.aarch64.rpm openssh-askpass-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.aarch64.rpm

openssh</span>-cavs-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.aarch64.rpm

openssh</span>-clients-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.aarch64.rpm

openssh</span>-keycat-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.aarch64.rpm

openssh</span>-ldap-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.aarch64.rpm

openssh</span>-server-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.aarch64.rpm

pam_ssh_agent_auth</span>-<span style="color: rgba(128, 0, 128, 1)">0.10</span>.<span style="color: rgba(128, 0, 128, 1)">3</span>-<span style="color: rgba(128, 0, 128, 1)">9.9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.aarch64.rpm

mips64el:

openssh</span>-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.mips64el.rpm

openssh</span>-askpass-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.mips64el.rpm

openssh</span>-cavs-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.mips64el.rpm

openssh</span>-clients-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.mips64el.rpm

openssh</span>-keycat-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.mips64el.rpm

openssh</span>-ldap-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span>.p02.ky10.mips64el.rpmopenssh-server-<span style="color: rgba(128, 0, 128, 1)">8</span>.2p1-<span style="color: rgba(128, 0, 128, 1)">9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.mips64el.rpm

      pam_ssh_agent_auth</span>-<span style="color: rgba(128, 0, 128, 1)">0.10</span>.<span style="color: rgba(128, 0, 128, 1)">3</span>-<span style="color: rgba(128, 0, 128, 1)">9.9</span><span style="color: rgba(0, 0, 0, 1)">.p02.ky10.mips64el.rpm



</span><span style="color: rgba(128, 0, 128, 1)">5</span><span style="color: rgba(0, 0, 0, 1)">.修复方法

方法一:配置源进行升级安装

</span><span style="color: rgba(128, 0, 128, 1)">1</span><span style="color: rgba(0, 0, 0, 1)">)打开软件包源配置文件,根据仓库地址进行修改

            银河麒麟高级服务器操作系统V10(SP1)

            仓库源地址:aarch64:http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/aarch64/</span>
<span style="color: rgba(0, 0, 0, 1)">
                                  x86_64:http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/x86_64/</span>
<span style="color: rgba(0, 0, 0, 1)">
                                  mips64el:http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/mips64el/</span>

<span style="color: rgba(128, 0, 128, 1)">2</span><span style="color: rgba(0, 0, 0, 1)">)配置完成后执行更新命令进行升级,命令如下:yum update openssh

方法二:下载安装包进行升级安装

         通过软件包地址下载软件包,使用软件包升级命令根据受影响的软件包列表进行升级安装,命令如下:rpm </span>-<span style="color: rgba(0, 0, 0, 1)">Uvh Packagelists



</span><span style="color: rgba(128, 0, 128, 1)">6</span><span style="color: rgba(0, 0, 0, 1)">. 软件包下载地址

银河麒麟高级服务器操作系统V10(SP1):

Openssh X86_64软件包下载地址:

http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/x86_64/Packages/openssh-8.2p1-9.p02.ky10.x86_64.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/x86_64/Packages/openssh-askpass-8.2p1-9.p02.ky10.x86_64.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/x86_64/Packages/openssh-cavs-8.2p1-9.p02.ky10.x86_64.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/x86_64/Packages/openssh-clients-8.2p1-9.p02.ky10.x86_64.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/x86_64/Packages/openssh-keycat-8.2p1-9.p02.ky10.x86_64.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/x86_64/Packages/openssh-ldap-8.2p1-9.p02.ky10.x86_64.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/x86_64/Packages/openssh-server-8.2p1-9.p02.ky10.x86_64.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/x86_64/Packages/pam_ssh_agent_auth-0.10.3-9.9.p02.ky10.x86_64.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
Openssh aarch64软件包下载地址:



<span style="font-size: 14pt">http:</span></span><span style="font-size: 14pt"><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/aarch64/Packages/openssh-8.2p1-9.p02.ky10.aarch64.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/aarch64/Packages/openssh-askpass-8.2p1-9.p02.ky10.aarch64.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/aarch64/Packages/openssh-cavs-8.2p1-9.p02.ky10.aarch64.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/aarch64/Packages/openssh-clients-8.2p1-9.p02.ky10.aarch64.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/aarch64/Packages/openssh-keycat-8.2p1-9.p02.ky10.aarch64.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/aarch64/Packages/openssh-ldap-8.2p1-9.p02.ky10.aarch64.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/aarch64/Packages/openssh-server-8.2p1-9.p02.ky10.aarch64.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/aarch64/Packages/pam_ssh_agent_auth-0.10.3-9.9.p02.ky10.aarch64.rpm</span></span>
<span style="color: rgba(0, 0, 0, 1)">
Openssh mips64el软件包下载地址:

http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/mips64el/Packages/openssh-8.2p1-9.p02.ky10.mips64el.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/mips64el/Packages/openssh-askpass-8.2p1-9.p02.ky10.mips64el.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/mips64el/Packages/openssh-cavs-8.2p1-9.p02.ky10.mips64el.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/mips64el/Packages/openssh-clients-8.2p1-9.p02.ky10.mips64el.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/mips64el/Packages/openssh-keycat-8.2p1-9.p02.ky10.mips64el.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/mips64el/Packages/openssh-ldap-8.2p1-9.p02.ky10.mips64el.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/mips64el/Packages/openssh-server-8.2p1-9.p02.ky10.mips64el.rpm</span>
<span style="color: rgba(0, 0, 0, 1)">
http:</span><span style="color: rgba(0, 128, 0, 1)">//</span><span style="color: rgba(0, 128, 0, 1)">update.cs2c.com.cn:8080/NS/V10/V10SP1/os/adv/lic/updates/mips64el/Packages/pam_ssh_agent_auth-0.10.3-9.9.p02.ky10.mips64el.rpm</span></pre>
</div>
<p>通过下载相关软件,上传服务器,进行rpm更新升级。</p>
<p>&nbsp;</p><br><br>
来源:https://www.cnblogs.com/ybinshi/p/15511825.html
頁: [1]
查看完整版本: 银河麒麟V10系统openssh漏洞修复