TSLSA-2002-0047 - openssh

From: Trustix Secure Linux Advisor (tslat_private)
Date: Mon Apr 29 2002 - 07:18:05 PDT

  • Next message: ppp-design: "Blahz-DNS: Authentication bypass vulnerability"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - --------------------------------------------------------------------------
    Trustix Secure Linux Security Advisory #2002-0047
    
    Package name:      openssh
    Summary:           Minor security issue.
    Date:              2002-04-29
    Affected versions: TSL 1.1, 1.2, 1.5
    
    - --------------------------------------------------------------------------
    
    Problem description:
      When rebuilding the old openssh package with support for kerberos, one
      could potentially become vulnerable to a local root exploit. TSL is not
      shipped with Kerberos by default nor is the openssh packages compiled with
      kerberos support, but since we do expect some people to rebuild the src-rpm 
      with kerberos support enabled, we like to upgrade the package.
    
    Action:
      We recommend that all systems with this package installed are upgraded.
      Please note that if you do not need the functionality provided by this
      package, you may want to remove it from your system.
    
    
    Location:
      All TSL updates are available from
      <URI:http://www.trustix.net/pub/Trustix/updates/>
      <URI:ftp://ftp.trustix.net/pub/Trustix/updates/>
    
    
    Automatic updates:
      Users of the SWUP tool can enjoy having updates automatically
      installed using 'swup --upgrade'.
    
      Get SWUP from:
      <URI:ftp://ftp.trustix.net/pub/Trustix/software/swup/>
    
    
    Public testing:
      These packages have been available for public testing for some time.
      If you want to contribute by testing the various packages in the
      testing tree, please feel free to share your findings on the
      tsl-discuss mailinglist.
      The testing tree is located at
      <URI:http://www.trustix.net/pub/Trustix/testing/>
      <URI:ftp://ftp.trustix.net/pub/Trustix/testing/>
      
    
    Questions?
      Check out our mailing lists:
      <URI:http://www.trustix.net/support/>
    
    
    Verification:
      This advisory along with all TSL packages are signed with the TSL sign key.
      This key is available from:
      <URI:http://www.trustix.net/TSL-GPG-KEY>
    
      The advisory itself is available from the errata pages at
      <URI:http://www.trustix.net/errata/trustix-1.2/> and
      <URI:http://www.trustix.net/errata/trustix-1.5/>
      or directly at
      <URI:http://www.trustix.net/errata/misc/2002/TSL-2002-0047-openssh.asc.txt>
    
    
    MD5sums of the packages:
    - --------------------------------------------------------------------------
    9d6b0684339eaf718b4a32495f786a62  ./1.5/SRPMS/openssh-3.1.0p1-3tr.src.rpm
    f00b0fa1bf6f52826cf8623893501781  ./1.5/RPMS/openssh-server-3.1.0p1-3tr.i586.rpm
    20a431fd990edfb51f62cf80c7298d82  ./1.5/RPMS/openssh-clients-3.1.0p1-3tr.i586.rpm
    1c39ad2e73c23d6bcfbaf85766f341b6  ./1.5/RPMS/openssh-3.1.0p1-3tr.i586.rpm
    9d6b0684339eaf718b4a32495f786a62  ./1.2/SRPMS/openssh-3.1.0p1-3tr.src.rpm
    485e8bc57115a14bdd4b7fab5cea9fd4  ./1.2/RPMS/openssh-server-3.1.0p1-3tr.i586.rpm
    5ca72211bea9a53858f7e815c4653efc  ./1.2/RPMS/openssh-clients-3.1.0p1-3tr.i586.rpm
    d88579917fed5ee9b6a4da58a66c9cd0  ./1.2/RPMS/openssh-3.1.0p1-3tr.i586.rpm
    9d6b0684339eaf718b4a32495f786a62  ./1.1/SRPMS/openssh-3.1.0p1-3tr.src.rpm
    c72fe0dee9af01565bb352112ad1928b  ./1.1/RPMS/openssh-server-3.1.0p1-3tr.i586.rpm
    e7d5808e75537a800fed61ff38c39f93  ./1.1/RPMS/openssh-clients-3.1.0p1-3tr.i586.rpm
    733cda90f84e9d3e35dcb03ec035bf4b  ./1.1/RPMS/openssh-3.1.0p1-3tr.i586.rpm
    - --------------------------------------------------------------------------
    
    
    Trustix Security Team
    
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.6 (GNU/Linux)
    Comment: For info see http://www.gnupg.org
    
    iD8DBQE8zTuFwRTcg4BxxS0RAvCeAJ9AU1n0cRA3X7uKUDpI8xJLp0bNRQCfbDrQ
    c9hNPmhrnmckqqtBHULAinI=
    =8YRS
    -----END PGP SIGNATURE-----
    



    This archive was generated by hypermail 2b30 : Mon Apr 29 2002 - 13:52:07 PDT