Informational
Informational
日本語による情報は、英語による原文の非公式な翻訳であり、英語原文との間で内容の齟齬がある場合には、英語原文が優先します。
概要
これは、Alex Lansteinがメッセージで述べた2005年12月16日に公開されたCisco Clean AccessのDoSに対するBugtraqメーリングリストへのCisco PSIRTの回答です。レポートのアーカイブ版は次の場所にあります。
http://www.securityfocus.com/archive/1/419645/30/0/threaded
Cisco では、研究者と協力してセキュリティ脆弱性に関する調査を進め、製品レポートで発表することを常に歓迎しています。
追加情報
この問題は、Cisco Bug ID:
CSCsc85405(登録ユーザ専用):廃止されたJSPがCAMにDoS攻撃を仕掛ける可能性
このDDTSはすでに解決されており、修正が利用可能です。
Cisco Clean Access Manager(CAM)をサービス拒否(DoS)攻撃にさらしたままにするために、廃止された特定のJSPファイルを利用する可能性があることが判明しました。
パッチは次の場所からお客様がダウンロードできます。
http://www.cisco.com/pcgi-bin/tablebuild.pl/cca-patches?psrtdcat20e2
次の情報は、CSCsc85405のパッチに付属するREADMEファイルに記載されています。この問題の詳細については、READMEを参照してください。
To address and fix this vulnerability, you must remove the obsolete
JSP files from your CAM as they are no longer needed. You can either:
1. Install the patch on your CAM, as described in "Patch Installation Intructions" below, or
2. Apply the workaround, as described in "Workaround Solution" below.
Caveat CSCsc85405 will be resolved in the following future releases:
* Cisco Clean Access release 3.5(9) and above
* Cisco Clean Access release 3.6.0.1 and above
===============================
Patch Installation Instructions
===============================
To install this patch:
1. Download the Patch-CSCsc85405.tar.gz file from the Cisco Clean
Access Patches folder
(http://www.cisco.com/pcgi-bin/tablebuild.pl/cca-patches) under Cisco
Secure Software
(http://www.cisco.com/public/sw-center/ciscosecure/cleanaccess.shtml).
2. Open an SSH terminal and copy the patch file into your Clean
Access Manager (CAM) using WinSCP, SSH File Transfer or PSCP, as
described below.
If using WinSCP or SSH File Transfer:
a. Copy Patch-CSCsc85405.tar.gz to the /store directory
on the Clean Access Manager.
If using PSCP:
a. Open a command prompt on your Windows computer.
b. Cd to the path where your PSCP resides
(e.g, C:\Documents and Settings\desktop).
c. Enter the following command to copy the file to the CAM:
pscp Patch-CSCsc85405.tar.gz root@ipaddress_manager:/store
3. From the SSH terminal, untar the patch file on the CAM:
cd /store
tar xzvf Patch-CSCsc85405.tar.gz
4. Cd to the Patch-CSCsc85405 directory:
cd Patch-CSCsc85405
5. Execute the patch file upgrade on the CAM:
./patch.sh
=========================
Workaround Solution
=========================
The following workaround steps remove the affected .jsp files from the
CAM, as they are no longer needed.
1. Open an SSH terminal, and login to the CAM shell.
2. Change directory as follows:
cd /perfigo/control/tomcat/webapps/admin/
3. Remove the uploadclient.jsp and ieee8021x.jsp files:
rm -f uploadclient.jsp ieee8021x.jsp
4. Change directory as follows:
cd /perfigo/control/tomcat/work/Standalone/localhost/admin
5. Remove the cached jsp sources:
rm -f uploadclient_jsp.* ieee8021x_jsp.*
6. Remove any file in the "installer/window" directory, this will be
useful for any exploited machine.
rm -f /perfigo/control/tomcat/normal-webapps/installer/windows/*
シスコのセキュリティ手順
シスコ製品のセキュリティの脆弱性に関するレポート、セキュリティ障害に対する支援、およびシスコからのセキュリティ情報を受信するための登録に関するすべての情報は、シスコのワールドワイド ウェブサイト https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html から入手できます。この情報には、シスコのセキュリティ通知に関して、報道機関が問い合せる場合の説明も含まれています。すべての Cisco セキュリティ アドバイザリは、http://www.cisco.com/go/psirt から入手できます。
URL
改訂履歴
利用規約
本アドバイザリは無保証のものとしてご提供しており、いかなる種類の保証も示唆するものではありません。 本アドバイザリの情報およびリンクの使用に関する責任の一切はそれらの使用者にあるものとします。 また、シスコは本ドキュメントの内容を予告なしに変更したり、更新したりする権利を有します。
本アドバイザリの記述内容に関して情報配信の URL を省略し、単独の転載や意訳を施した場合、当社が管理した情報とは見なされません。そうした情報は、事実誤認を引き起こしたり、重要な情報が欠落していたりする可能性があります。 このドキュメントの情報は、シスコ製品のエンドユーザを対象としています。