Date: Mon, 11 Mar 2002 08:52:33 +0100
From: (Trustix Secure Linux Advisor) <[email protected]>
To: [email protected]Subject: TSLSA-2002-0039 - openssh
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- --------------------------------------------------------------------------
Trustix Secure Linux Security Advisory #2002-0039
Package name: openssh
Summary: Version upgrade security fix
Date: 2002-03-07
Affected versions: TSL 1.1, 1.2, 1.5
- --------------------------------------------------------------------------
Problem description:
Users with an existing user account could potentially abuse a bug
to in the channel code and gain root privileges. Exploitability without an
existing user account has not been proven but is not considered impossible.
Action:
We recommend that all systems with this package installed are upgraded.
Please note that if you do not need the functionality provided by this
package, you may want to remove it from your system.
Location:
All TSL updates are available from
<URI:http://www.trustix.net/pub/Trustix/updates/>
<URI:ftp://ftp.trustix.net/pub/Trustix/updates/>
Automatic updates:
Users of the SWUP tool can enjoy having updates automatically
installed using 'swup --upgrade'.
Get SWUP from:
<URI:ftp://ftp.trustix.net/pub/Trustix/software/swup/>
Public testing:
These packages have been available for public testing for some time.
If you want to contribute by testing the various packages in the
testing tree, please feel free to share your findings on the
tsl-discuss mailinglist.
The testing tree is located at
<URI:http://www.trustix.net/pub/Trustix/testing/>
<URI:ftp://ftp.trustix.net/pub/Trustix/testing/>
Questions?
Check out our mailing lists:
<URI:http://www.trustix.net/support/>
Verification:
This advisory along with all TSL packages are signed with the TSL sign key.
This key is available from:
<URI:http://www.trustix.net/TSL-GPG-KEY>
The advisory itself is available from the errata pages at
<URI:http://www.trustix.net/errata/trustix-1.2/> and
<URI:http://www.trustix.net/errata/trustix-1.5/>
or directly at
<URI:http://www.trustix.net/errata/misc/2002/TSL-2002-0039-default.asc.txt>
MD5sums of the packages:
- --------------------------------------------------------------------------
9e1e15c8b4dce51f6158445d19c3b82e ./1.5/SRPMS/openssh-3.1.0p1-1tr.src.rpm
ea1ce72d57e85fd802254ea760be2381 ./1.5/RPMS/openssh-server-3.1.0p1-1tr.i586.rpm
4692b3ac3cf452f0b0b0d00312befdce ./1.5/RPMS/openssh-clients-3.1.0p1-1tr.i586.rpm
e9ca3b690ee49b0c6b85586b69b94b1c ./1.5/RPMS/openssh-3.1.0p1-1tr.i586.rpm
9e1e15c8b4dce51f6158445d19c3b82e ./1.2/SRPMS/openssh-3.1.0p1-1tr.src.rpm
912d7dee5c77776273d4a6575310c42c ./1.2/RPMS/openssh-server-3.1.0p1-1tr.i586.rpm
6fd3a02182797cd64a6d97c03ec68780 ./1.2/RPMS/openssh-clients-3.1.0p1-1tr.i586.rpm
b14bfb5a6d1c28f087a63afdd93cf10a ./1.2/RPMS/openssh-3.1.0p1-1tr.i586.rpm
9e1e15c8b4dce51f6158445d19c3b82e ./1.1/SRPMS/openssh-3.1.0p1-1tr.src.rpm
dc5f36291b4b74d8106fe2de6e2c74a3 ./1.1/RPMS/openssh-server-3.1.0p1-1tr.i586.rpm
0ae4711f02c3c83c978758f8a79f1da4 ./1.1/RPMS/openssh-clients-3.1.0p1-1tr.i586.rpm
b458a0887b8cfde9e700ace3dd37a521 ./1.1/RPMS/openssh-3.1.0p1-1tr.i586.rpm
- --------------------------------------------------------------------------
Trustix Security Team
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org
iD8DBQE8h5v/wRTcg4BxxS0RAnk3AJ4769VvnRQnQhkLx9jDfdj3YFB1RQCdFLQg
EPQvB1NQNeNMnPgtbRjndlQ=
=870B
-----END PGP SIGNATURE-----