Portable OpenSSH versions 3.7p1 and 3.7.1p1 contain multiplevulnerabilities in the new PAM code. At least one of these bugsis remotely exploitable (under a non-standard configuration,with privsep disabled).. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200309-14 - - - --------------------------------------------------------------------- PACKAGE : openssh SUMMARY : multiple vulnerabilities in new PAM code DATE : 2003-09-23 20:25 UTC EXPLOIT : remote VERSIONS AFFECTED : =openssh-3.7.1_p2 CVE : - - - --------------------------------------------------------------------- quote from advisory: "Portable OpenSSH versions 3.7p1 and 3.7.1p1 contain multiple vulnerabilities in the new PAM code. At least one of these bugs is remotely exploitable (under a non-standard configuration, with privsep disabled)." read the full advisory at: openssh SOLUTION It is recommended that all Gentoo Linux users who are running net-misc/openssh upgrade to openssh-3.7.1_p2 as follows: emerge sync emerge openssh emerge clean - - - ---------------------------------------------------------------------
Get the latest Linux and open source security news straight to your inbox.