Security Advisory Updated openssh packages available for Red Hat Linux 7

Advisory: RHSA-2000:111-04
Type: Security Advisory
Severity: N/A
Issued on: 2000-11-27
Last updated on: 2000-11-27
Affected Products: Red Hat Linux 7.0
OVAL: N/A
CVEs (cve.mitre.org): CVE-2000-1169

Details

Updated openssh packages are now available for Red Hat Linux 7.

2000-11-27: Added packages for Red Hat Linux 7 for Alpha

An OpenSSH client will do agent or X11 forwarding at the request of a
server, even if the user has not requested that it be done. A malicious
server can exploit this vulnerability to gain access to the user's
display.


Solution

For each RPM for your particular architecture, run:

rpm -Fvh [filename]

where filename is the name of the RPM.

Updated packages

Red Hat Linux 7.0

alpha:
ftp://updates.redhat.com/7.0/alpha/openssh-2.3.0p1-4.alpha.rpm
Missing file
    cfa7b84d1389e921d11cd93888014bbe
ftp://updates.redhat.com/7.0/alpha/openssh-askpass-2.3.0p1-4.alpha.rpm
Missing file
    59464df875127cc44ca1976db62bb977
ftp://updates.redhat.com/7.0/alpha/openssh-askpass-gnome-2.3.0p1-4.alpha.rpm
Missing file
    957467291fc0067d70bef99c88401dcf
ftp://updates.redhat.com/7.0/alpha/openssh-clients-2.3.0p1-4.alpha.rpm
Missing file
    da26d6a308c2c3c79f56eec077bce664
ftp://updates.redhat.com/7.0/alpha/openssh-server-2.3.0p1-4.alpha.rpm
Missing file
    5e4951bc163601aad8733011933d79db
 
i386:
ftp://updates.redhat.com/7.0/i386/openssh-2.3.0p1-4.i386.rpm
Missing file
    973c033bd3cf3e3641f7fb9d172baf5a
ftp://updates.redhat.com/7.0/i386/openssh-askpass-2.3.0p1-4.i386.rpm
Missing file
    ead1cc84519f5a6fa0233ce8d3237457
ftp://updates.redhat.com/7.0/i386/openssh-askpass-gnome-2.3.0p1-4.i386.rpm
Missing file
    d426ff6c55181f8ccbea6e2f7a307b99
ftp://updates.redhat.com/7.0/i386/openssh-clients-2.3.0p1-4.i386.rpm
Missing file
    51fe082e6830e461a900000e2884cb14
ftp://updates.redhat.com/7.0/i386/openssh-server-2.3.0p1-4.i386.rpm
Missing file
    dd9bb3271403162202599d3cd8b9a22e
 

Bugs fixed (see bugzilla for more information)

20884 - openssh-2.3.0p1 doesn't include /etc/ssh/primes


References


Keywords

forwarding


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/