Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Slackware 14.1 SSA:2014-293-01 Critical OpenSSH DNS Issue

slackware
Calendar Grey October 20, 2014
Dist Slackware Esm H88
Recent updates to openssh packages for Slackware address a serious security vulnerability concerning the verification of SSHFP DNS resource records.
New openssh packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue

Summary

Here are the details from the Slackware 14.1 ChangeLog: patches/packages/openssh-6.7p1-i486-1_slack14.1.txz: Upgraded. This update fixes a security issue that allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate. For more information, see: https://www.cve.org/CVERecord?id=CVE-2014-2653 (* Security fix *) Thanks to mancha for the backported patch used for Slackware 13.0 - 13.37.

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 13.0:
Updated package for Slackware x86_64 13.0:
Updated package for Slackware 13.1:
Updated package for Slackware x86_64 13.1:
Updated package for Slackware 13.37:
Updated package for Slackware x86_64 13.37:
Updated package for Slackware 14.0:
Updated package for Slackware x86_64 14.0:
Updated package for Slackware 14.1:
Updated package for Slackware x86_64 14.1:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:

MD5 Signatures

Slackware 13.0 package: 23a13f3f01617fe124008babcdda547b openssh-5.9p1-i486-2_slack13.0.txz
Slackware x86_64 13.0 package: c5cb8a7331caaecf548222a01125f965 openssh-5.9p1-x86_64-2_slack13.0.txz
Slackware 13.1 package: a1b912d4288156650b8c50d460fca534 openssh-5.9p1-i486-2_slack13.1.txz
Slackware x86_64 13.1 package: b676f089da3f94ae4640d83ca29745ae openssh-5.9p1-x86_64-2_slack13.1.txz
Slackware 13.37 package: 0b4109ec7196b30ca2358e56dff5196f openssh-5.9p1-i486-2_slack13.37.txz
Slackware x86_64 13.37 package: 14d5cf3fc246c67b486af80b7b61ef12 openssh-5.9p1-x86_64-2_slack13.37.txz
Slackware 14.0 package: 193f0b568921ae1087a92286e5fc2891 openssh-6.7p1-i486-1_slack14.0.txz
Slackware x86_64 14.0 package: 695bf6c6cf838a29f7e28eb67753e169 openssh-6.7p1-x86_64-1_slack14.0.txz
Slackware 14.1 package: a334cd16dbe08ed8d406c2517268bbdd openssh-6.7p1-i486-1_slack14.1.txz
Slackware x86_64 14.1 package: fbada742b1ee2ab24b2105a84c9332f4 openssh-6.7p1-x86_64-1_slack14.1.txz
Slackware -current package: f90503da3c213ed20effcff9d21324b3 n/openssh-6.7p1-i486-1.txz
Slackware x86_64 -current package: 1a6f93c3529e4b957e5df5f6566a6160 n/openssh-6.7p1-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg openssh-6.7p1-i486-1_slack14.1.txz Next, restart the sshd daemon: # sh /etc/rc.d/rc.sshd restart

Related News

Your message here