Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Gentoo: 202310-25 High: Apache2 Remote Code Execution Vulnerability

gentoo
Calendar Grey September 23, 2003
Dist Gentoo Esm H88
The latest updates for Portable OpenSSH have revealed several vulnerabilities linked to PAM; users are highly recommended to upgrade promptly to reduce potential security threats.
Portable OpenSSH versions 3.7p1 and 3.7.1p1 contain multiplevulnerabilities in the new PAM code

Summary


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
GENTOO LINUX SECURITY ANNOUNCEMENT 200309-14



quote from advisory:
"Portable OpenSSH versions 3.7p1 and 3.7.1p1 contain multiple vulnerabilities in the new PAM code. At least one of these bugs is remotely exploitable (under a non-standard configuration, with privsep disabled)."
read the full advisory at: openssh
SOLUTION
It is recommended that all Gentoo Linux users who are running net-misc/openssh upgrade to openssh-3.7.1_p2 as follows:
emerge sync emerge openssh emerge clean
aliz@gentoo.org - GnuPG key is available at -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (GNU/Linux)
iD8DBQE/cKxBfT7nyhUpoZMRAmw0AJ92FPN0+E9Sm30c8B8rjF31/gQ7UwCcCWmi ZSsCQAtKpTlq4M/KTdfMQ5M=mEO/ -----END PGP SIGNATURE-----


Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
important
Lowest
Low
Medium
High
Critical

PACKAGE : openssh
SUMMARY : multiple vulnerabilities in new PAM code
DATE : 2003-09-23 20:25 UTC
EXPLOIT : remote
VERSIONS AFFECTED : =openssh-3.7.1_p2
CVE :

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here