Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian 3.0 DSA-134-1 Critical: OpenSSH Remote Access Exploit

debian
Calendar Grey June 24, 2002
Debian Logo
The latest announcement from Ubuntu concerning OpenSSH security flaws underscores the importance of prompt patching to ensure system safety. Critical information provided.
Theo de Raadt announced that the OpenBSD team is working with ISSon a remote exploit for OpenSSH

Summary

Package : ssh
Problem type : remote exploit
Debian-specific: no

Theo de Raadt announced that the OpenBSD team is working with ISS
on a remote exploit for OpenSSH (a free implementation of the
Secure SHell protocol). They are refusing to provide any details on
the vulnerability but instead are advising everyone to upgrade to
the latest release, version 3.3.

This version was released 3 days ago and introduced a new feature
to reduce the effect of exploits in the network handling code
called privilege separation. Unfortunately this release has a few
known problems: compression does not work on all operating systems
since the code relies on specific mmap features, and the PAM
support has not been completed. There may be other problems as
well.

The new privilege separation support from Niels Provos changes ssh
to use a separate non-privileged process to handle most of the
work. This means any vulnerability in this part of OpenSSH can
never lead to a root compromise but only to access to a separate
...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here