[Please upgrade OpenSSH... again -- Raju] This is an RFC 1153 digest. (1 message) ----------------------------------------------------------------------
Message-Id: <[EMAIL PROTECTED]> From: [EMAIL PROTECTED] (Daniel Ahlberg) To: [EMAIL PROTECTED], [EMAIL PROTECTED], [EMAIL PROTECTED] Subject: GLSA: openssh (200309-14) Date: Tue, 23 Sep 2003 22:25:37 +0200 (CEST) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200309-14 - - - --------------------------------------------------------------------- � � � � � PACKAGE : openssh � � � � � SUMMARY : multiple vulnerabilities in new PAM code � � � � � � �DATE : 2003-09-23 20:25 UTC � � � � � EXPLOIT : remote VERSIONS AFFECTED : <openssh-3.7.1_p2 � � FIXED VERSION : >=openssh-3.7.1_p2 � � � � � � � CVE : - - - --------------------------------------------------------------------- quote from advisory: "Portable OpenSSH versions 3.7p1 and 3.7.1p1 contain multiple vulnerabilities in the new PAM code. At least one of these bugs is remotely exploitable (under a non-standard configuration, with privsep disabled)." read the full advisory at: http://www.openssh.com/txt/sshpam.adv SOLUTION It is recommended that all Gentoo Linux users who are running net-misc/openssh upgrade to openssh-3.7.1_p2 as follows: emerge sync emerge openssh emerge clean - - - --------------------------------------------------------------------- [EMAIL PROTECTED] - GnuPG key is available at http://dev.gentoo.org/~aliz - - - --------------------------------------------------------------------- -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (GNU/Linux) iD8DBQE/cKxBfT7nyhUpoZMRAmw0AJ92FPN0+E9Sm30c8B8rjF31/gQ7UwCcCWmi ZSsCQAtKpTlq4M/KTdfMQ5M= =mEO/ -----END PGP SIGNATURE----- ------------------------------ End of this Digest ****************** -- Raj Mathur [EMAIL PROTECTED] http://kandalaya.org/ GPG: 78D4 FC67 367F 40E2 0DD5 0FEF C968 D0EF CC68 D17F All your domain are belong to us. It is the mind that moves _______________________________________________ ilugd mailing list [EMAIL PROTECTED] http://frodo.hserus.net/mailman/listinfo/ilugd
