Bug Fix Advisory Updated openssh packages

Advisory: RHBA-2004:303-03
Type: Bug Fix Advisory
Severity: N/A
Issued on: 2004-08-05
Last updated on: 2004-08-05
Affected Products: Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux WS (v. 2.1)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
OVAL: N/A

Details

Updated openssh packages that include a bug fix are now available for Red
Hat Enterprise Linux 2.1.

OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. SSH
replaces rlogin and rsh, providing secure encrypted communications between
two untrusted hosts over an insecure network. X11 connections and arbitrary
TCP/IP ports can also be forwarded over the secure channel. Public key
authentication may be used for "passwordless" access to servers.

These updated packages corrected a bug which prevented sshd from properly
manipulating the /var/log/lastlog entry for users with very high UIDs.

When manipulating the entry in /var/log/lastlog, which corresponds to a
given user, sshd calculates the location of the entry by multiplying the
UID and the length of an entry in the file. On some systems, the
result of this calculation would mistakenly be truncated to 32 bits for
users with sufficiently high UIDs.

All users of openssh should upgrade to these updated packages, which
resolve this issue.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

If up2date fails to connect to Red Hat Network due to SSL
Certificate Errors, you need to install a version of the
up2date client with an updated certificate. The latest version of
up2date is available from the Red Hat FTP site and may also be
downloaded directly from the RHN website:

https://rhn.redhat.com/help/latest-up2date.pxt

Updated packages

Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
openssh-3.1p1-15.src.rpm
File outdated by:  RHSA-2006:0698
    f76104a6c04127dbb4a66b12f1e5a50d
 
IA-32:
openssh-3.1p1-15.i386.rpm
File outdated by:  RHSA-2006:0698
    58c25a12d8cd93647507bfdadd07f2c1
openssh-askpass-3.1p1-15.i386.rpm
File outdated by:  RHSA-2006:0698
    6a9c0b3bb236bcbd2f0b6ddc0fbea47c
openssh-askpass-gnome-3.1p1-15.i386.rpm
File outdated by:  RHSA-2006:0698
    6d29a69889880611e66ecd6c913324ba
openssh-clients-3.1p1-15.i386.rpm
File outdated by:  RHSA-2006:0698
    e1acceec9fe806596051fd83e4d097f4
openssh-server-3.1p1-15.i386.rpm
File outdated by:  RHSA-2006:0698
    d452e08358a5d85659ed08814b5b56f9
 
IA-64:
openssh-3.1p1-15.ia64.rpm
File outdated by:  RHSA-2006:0698
    c1765fbfbf758fe2aed8fe124a7fff8f
openssh-askpass-3.1p1-15.ia64.rpm
File outdated by:  RHSA-2006:0698
    0e48f82092421d14b6fce94fc2943e26
openssh-askpass-gnome-3.1p1-15.ia64.rpm
File outdated by:  RHSA-2006:0698
    f38bd00a535c4e2523588a869d50ae65
openssh-clients-3.1p1-15.ia64.rpm
File outdated by:  RHSA-2006:0698
    3e50dad7d636807393476e776e02525e
openssh-server-3.1p1-15.ia64.rpm
File outdated by:  RHSA-2006:0698
    c18218df380e44e01c57f7e162834745
 
Red Hat Enterprise Linux ES (v. 2.1)

SRPMS:
openssh-3.1p1-15.src.rpm
File outdated by:  RHSA-2006:0698
    f76104a6c04127dbb4a66b12f1e5a50d
 
IA-32:
openssh-3.1p1-15.i386.rpm
File outdated by:  RHSA-2006:0698
    58c25a12d8cd93647507bfdadd07f2c1
openssh-askpass-3.1p1-15.i386.rpm
File outdated by:  RHSA-2006:0698
    6a9c0b3bb236bcbd2f0b6ddc0fbea47c
openssh-askpass-gnome-3.1p1-15.i386.rpm
File outdated by:  RHSA-2006:0698
    6d29a69889880611e66ecd6c913324ba
openssh-clients-3.1p1-15.i386.rpm
File outdated by:  RHSA-2006:0698
    e1acceec9fe806596051fd83e4d097f4
openssh-server-3.1p1-15.i386.rpm
File outdated by:  RHSA-2006:0698
    d452e08358a5d85659ed08814b5b56f9
 
Red Hat Enterprise Linux WS (v. 2.1)

SRPMS:
openssh-3.1p1-15.src.rpm
File outdated by:  RHSA-2006:0698
    f76104a6c04127dbb4a66b12f1e5a50d
 
IA-32:
openssh-3.1p1-15.i386.rpm
File outdated by:  RHSA-2006:0698
    58c25a12d8cd93647507bfdadd07f2c1
openssh-askpass-3.1p1-15.i386.rpm
File outdated by:  RHSA-2006:0698
    6a9c0b3bb236bcbd2f0b6ddc0fbea47c
openssh-askpass-gnome-3.1p1-15.i386.rpm
File outdated by:  RHSA-2006:0698
    6d29a69889880611e66ecd6c913324ba
openssh-clients-3.1p1-15.i386.rpm
File outdated by:  RHSA-2006:0698
    e1acceec9fe806596051fd83e4d097f4
openssh-server-3.1p1-15.i386.rpm
File outdated by:  RHSA-2006:0698
    d452e08358a5d85659ed08814b5b56f9
 
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor

SRPMS:
openssh-3.1p1-15.src.rpm
File outdated by:  RHSA-2006:0698
    f76104a6c04127dbb4a66b12f1e5a50d
 
IA-64:
openssh-3.1p1-15.ia64.rpm
File outdated by:  RHSA-2006:0698
    c1765fbfbf758fe2aed8fe124a7fff8f
openssh-askpass-3.1p1-15.ia64.rpm
File outdated by:  RHSA-2006:0698
    0e48f82092421d14b6fce94fc2943e26
openssh-askpass-gnome-3.1p1-15.ia64.rpm
File outdated by:  RHSA-2006:0698
    f38bd00a535c4e2523588a869d50ae65
openssh-clients-3.1p1-15.ia64.rpm
File outdated by:  RHSA-2006:0698
    3e50dad7d636807393476e776e02525e
openssh-server-3.1p1-15.ia64.rpm
File outdated by:  RHSA-2006:0698
    c18218df380e44e01c57f7e162834745
 
(The unlinked packages above are only available from the Red Hat Network)

Keywords

lastlog, openssh, uid


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/