public inbox for gentoo-announce@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-announce] GLSA 200309-12: OpenSSH
@ 2003-09-17  1:52 Seemant Kulleen
  0 siblings, 0 replies; only message in thread
From: Seemant Kulleen @ 2003-09-17  1:52 UTC (permalink / raw
  To: gentoo-security, gentoo-announce

[-- Attachment #1: Type: text/plain, Size: 1782 bytes --]

- - -
---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200309-12
- - -
---------------------------------------------------------------------

     PACKAGE : openssh
     SUMMARY : buffer management error
      DATE : 2003-09-16 22:53 UTC
     EXPLOIT : remote
VERSIONS AFFECTED : <=openssh-3.7_p1
  FIXED VERSION : >=openssh-3.7.1_p1
       CVE : CAN-2003-0693

- - -
---------------------------------------------------------------------

quote from advisory:

"All versions of OpenSSH's sshd prior to 3.7 contain a buffer management
error.  It is uncertain whether this error is potentially
exploitable,however, we prefer to see bugs fixed proactively."

read the full advisory at:
http://www.openssh.com/txt/buffer.adv

This is a follow up advisory to indicate the further fixes have been
made.  From the ChangeLog:

 - (djm) OpenBSD Sync
    - markus@cvs.openbsd.org 2003/09/16 21:02:40
      [buffer.c channels.c version.h]
      more malloc/fatal fixes; ok millert/deraadt; ghudson at MIT.EDU

(reported on http://bugs.gentoo.org/show_bug.cgi?id=28927 by 
Christian Rubbert <ceed@xrc.de>)

SOLUTION

It is recommended that all Gentoo Linux users who are running
net-misc/openssh upgrade to openssh-3.7.1_p1 as follows:

emerge sync
emerge openssh
emerge clean

- - ---------------------------------------------------------------
seemant@gentoo.org - GnuPG key in signature below and on keyservers
vapier@gentoo.org

-- 
Seemant Kulleen
Developer and Project Co-ordinator,
Gentoo Linux					http://dev.gentoo.org/~seemant

Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x3458780E
Key fingerprint = 23A9 7CB5 9BBB 4F8D 549B 6593 EDA2 65D8 3458 780E


[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2003-09-17  2:21 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-09-17  1:52 [gentoo-announce] GLSA 200309-12: OpenSSH Seemant Kulleen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox