Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
98

Red Hat: RHSA-2000:111-04 Critical: OpenSSH Port Forwarding Risk

An OpenSSH client will do agent or X11 forwarding at the request of a server, even if the user has not requested that it be done.. ` --------------------------------------------------------------------- Red Hat, Inc. Security Advisory Synopsis: Updated openssh packages available for Red Hat Linux 7 Advisory ID: RHSA-2000:111-04 Issue date: 2000-11-20 Updated on: 2000-11-27 Product: Red Hat Linux Keywords: openssh malicious server port forwarding Cross references: N/A --------------------------------------------------------------------- 1. Topic: Updated openssh packages are now available for Red Hat Linux 7. 2000-11-27: Added packages for Red Hat Linux 7 for Alpha 2. Relevant releases/architectures: Red Hat Linux 7.0 - i386, alpha 3. Problem description: An OpenSSH client will do agent or X11 forwarding at the request of a server, even if the user has not requested that it be done. A malicious server can exploit this vulnerability to gain access to the user's display. 4. Solution: For each RPM for your particular architecture, run: rpm -Fvh [filename] where filename is the name of the RPM. 5. Bug IDs fixed ( for more info): 18598 - ssh-keygen -l does not work for dsa keys 20805 - Hostile servers can force OpenSSH clients to do agent or X11 forwarding 20884 - openssh-2.3.0p1 doesn't include /etc/ssh/primes 6. RPMs required: Red Hat Linux 7.0: alpha: i386: sources: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- d564b593cce6c1afaa02a11004ef6cf7 7.0/SRPMS/openssh-2.3.0p1-4.src.rpm cfa7b84d1389e921d11cd93888014bbe 7.0/alpha/openssh-2.3.0p1-4.alpha.rpm 59464df875127cc44ca1976db62bb977 7.0/alpha/openssh-askpass-2.3.0p1-4.alpha.rpm 957467291fc0067d70bef99c88401dcf 7.0/alpha/openssh-askpass-gnome-2.3.0p1-4.alpha.rpm da26d6a308c2c3c79f56eec077bce664 7.0/alpha/openssh-clients-2.3.0p1-4.alpha.rpm 5e4951bc163601aad8733011933d79db 7.0/alpha/openssh-server-2.3.0p1-4.alpha.rpm 973c033bd3cf3e3641f7fb9d172baf5a 7.0/i386/openssh-2.3.0p1-4.i386.rpm ead1cc84519f5a6fa0233ce8d3237457 7.0/i386/openssh-askpass-2.3.0p1-4.i386.rpm d426ff6c55181f8ccbea6e2f7a307b99 7.0/i386/openssh-askpass-gnome-2.3.0p1-4.i386.rpm 51fe082e6830e461a900000e2884cb14 7.0/i386/openssh-clients-2.3.0p1-4.i386.rpm dd9bb3271403162202599d3cd8b9a22e 7.0/i386/openssh-server-2.3.0p1-4.i386.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: OpenBSD 2.7 Errata Copyright(c) 2000 Red Hat, Inc. `. Updated OpenSSH packages launched for Red Hat Enterprise Linux 7 to mitigate risks associated with unapproved server entry.. openssh patching, Red Hat Linux update, security fix, software update, malicious access prevention. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 27, 2000 Critical Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here