10733711 2003-09-23 22:25 +0200 /47 rader/ Daniel Ahlberg <aliz@gentoo.org> Sänt av: gentoo-announce-return-159-11451=lyskom.lysator.liu.se@gentoo.org Importerad: 2003-09-23 22:18 av Brevbäraren Extern mottagare: gentoo-announce@gentoo.org Extern mottagare: bugtraq@securityfocus.com Extern mottagare: full-disclosure@lists.netsys.com Mottagare: Gentoo (-) mailimport <233> Mottagare: Bugtraq (import) <29177> Sänt: 2003-09-24 22:00 Ärende: [gentoo-announce] GLSA: openssh (200309-14) ------------------------------------------------------------ -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200309-14 - - - --------------------------------------------------------------------- PACKAGE : openssh SUMMARY : multiple vulnerabilities in new PAM code DATE : 2003-09-23 20:25 UTC EXPLOIT : remote VERSIONS AFFECTED : <openssh-3.7.1_p2 FIXED VERSION : >=openssh-3.7.1_p2 CVE : - - - --------------------------------------------------------------------- quote from advisory: "Portable OpenSSH versions 3.7p1 and 3.7.1p1 contain multiple vulnerabilities in the new PAM code. At least one of these bugs is remotely exploitable (under a non-standard configuration, with privsep disabled)." read the full advisory at: http://www.openssh.com/txt/sshpam.adv SOLUTION It is recommended that all Gentoo Linux users who are running net-misc/openssh upgrade to openssh-3.7.1_p2 as follows: emerge sync emerge openssh emerge clean - - - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at http://dev.gentoo.org/~aliz - - - --------------------------------------------------------------------- -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (GNU/Linux) iD8DBQE/cKxBfT7nyhUpoZMRAmw0AJ92FPN0+E9Sm30c8B8rjF31/gQ7UwCcCWmi ZSsCQAtKpTlq4M/KTdfMQ5M= =mEO/ -----END PGP SIGNATURE----- (10733711) /Daniel Ahlberg <aliz@gentoo.org>/------- Kommentar i text 10738549 av Ademar de Souza Reis Jr. <ademar@conectiva.com.br>