Security Advisory Updated openssh packages available

Advisory: RHSA-2001:114-05
Type: Security Advisory
Severity: N/A
Issued on: 2001-09-27
Last updated on: 2001-10-19
Affected Products: Red Hat Linux 7.0
Red Hat Linux 7.1
Red Hat Linux 7.2
OVAL: N/A
CVEs (cve.mitre.org): CVE-2001-1380

Details

Updated openssh packages are now available for Red Hat Linux 7 and 7.1.
These packages fix a vulnerability which may allow unauthorized users to
log in from hosts that have been denied access.

2001-10-22: Pacakges are now available for Red Hat Linux 7.2.

If a user lists multiple keys in her .ssh/authorized_keys2 file, sshd may
in some circumstances not honor the "from" option which can be associated
with a key, thereby allowing key-based logins from hosts which should not
be allowed access.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Linux 7.0

SRPMS:
openssh-2.9p2-8.7.src.rpm
File outdated by:  RHSA-2002:127
    2cb978dd97527b75dd765cc7866747be
 
Alpha:
openssh-2.9p2-8.7.alpha.rpm
File outdated by:  RHSA-2002:127
    3f25b21ea52cf287b3f92dde9ebeb6e5
openssh-askpass-2.9p2-8.7.alpha.rpm
File outdated by:  RHSA-2002:127
    0aa7e84cf7051625c266fd06097f5421
openssh-askpass-gnome-2.9p2-8.7.alpha.rpm
File outdated by:  RHSA-2002:127
    b0bc920fb83c38f91696283ae9a35c70
openssh-clients-2.9p2-8.7.alpha.rpm
File outdated by:  RHSA-2002:127
    3ba198d73c0c2b98b1d28b1209529704
openssh-server-2.9p2-8.7.alpha.rpm
File outdated by:  RHSA-2002:127
    b6190a028673032994ccc21cf2a1d620
 
IA-32:
openssh-2.9p2-8.7.i386.rpm
File outdated by:  RHSA-2002:127
    968125b43cb68330aa58a85e082573c6
openssh-askpass-2.9p2-8.7.i386.rpm
File outdated by:  RHSA-2002:127
    913350e14f7e40c1cbaaf01a68ff2af6
openssh-askpass-gnome-2.9p2-8.7.i386.rpm
File outdated by:  RHSA-2002:127
    62aac745851160f5805eaee52cdb6eb9
openssh-clients-2.9p2-8.7.i386.rpm
File outdated by:  RHSA-2002:127
    d2831ff8f3032462b511ec9bd8e486f2
openssh-server-2.9p2-8.7.i386.rpm
File outdated by:  RHSA-2002:127
    3a995bf67827eaa272976df85939d778
 
Red Hat Linux 7.1

SRPMS:
openssh-2.9p2-8.7.src.rpm
File outdated by:  RHSA-2002:127
    2cb978dd97527b75dd765cc7866747be
 
IA-32:
openssh-2.9p2-8.7.i386.rpm
File outdated by:  RHSA-2003:279
    968125b43cb68330aa58a85e082573c6
openssh-askpass-2.9p2-8.7.i386.rpm
File outdated by:  RHSA-2003:279
    913350e14f7e40c1cbaaf01a68ff2af6
openssh-askpass-gnome-2.9p2-8.7.i386.rpm
File outdated by:  RHSA-2003:279
    62aac745851160f5805eaee52cdb6eb9
openssh-clients-2.9p2-8.7.i386.rpm
File outdated by:  RHSA-2003:279
    d2831ff8f3032462b511ec9bd8e486f2
openssh-server-2.9p2-8.7.i386.rpm
File outdated by:  RHSA-2003:279
    3a995bf67827eaa272976df85939d778
 
IA-64:
openssh-2.9p2-8.7.ia64.rpm
File outdated by:  RHSA-2002:127
    d2cfbc8f711499f14e850e3a39216b72
openssh-askpass-2.9p2-8.7.ia64.rpm
File outdated by:  RHSA-2002:127
    676181a27221581a0144d5987d42e5d8
openssh-askpass-gnome-2.9p2-8.7.ia64.rpm
File outdated by:  RHSA-2002:127
    48455412e34bd704d6c7516f5ed8208c
openssh-clients-2.9p2-8.7.ia64.rpm
File outdated by:  RHSA-2002:127
    225d83ddfebb3eba7fe290c33c5c41cf
openssh-server-2.9p2-8.7.ia64.rpm
File outdated by:  RHSA-2002:127
    b6cfceece2ac8f5060ab63d6f7254770
 
alpha:
ftp://updates.redhat.com/7.1/en/os/alpha/openssh-2.9p2-8.7.alpha.rpm
Missing file
    917606bec87a2598db083075248d63f3
ftp://updates.redhat.com/7.1/en/os/alpha/openssh-askpass-2.9p2-8.7.alpha.rpm
Missing file
    59e697845982082983be668c1491f478
ftp://updates.redhat.com/7.1/en/os/alpha/openssh-askpass-gnome-2.9p2-8.7.alpha.rpm
Missing file
    b1a4c72deb5086d80b0065cd1ddf6ce4
ftp://updates.redhat.com/7.1/en/os/alpha/openssh-clients-2.9p2-8.7.alpha.rpm
Missing file
    16523f9c4e76c077dc10505fa1c46f2f
ftp://updates.redhat.com/7.1/en/os/alpha/openssh-server-2.9p2-8.7.alpha.rpm
Missing file
    4844484c7174ee970617579a4355639d
 
Red Hat Linux 7.2

SRPMS:
openssh-2.9p2-9.src.rpm
File outdated by:  RHSA-2003:279
    b8962a6f832e333d8fcf8782228f78e3
 
IA-32:
openssh-2.9p2-9.i386.rpm
File outdated by:  RHSA-2003:279
    c553416074a5fc54d309c6e7653f684a
openssh-askpass-2.9p2-9.i386.rpm
File outdated by:  RHSA-2003:279
    557a7615d1abf68e4b2bb998c0091638
openssh-askpass-gnome-2.9p2-9.i386.rpm
File outdated by:  RHSA-2003:279
    4b1df978407683e2c160f496f24e26e5
openssh-clients-2.9p2-9.i386.rpm
File outdated by:  RHSA-2003:279
    f35d0f0b45fd5fd3ceb06589ca18aab3
openssh-server-2.9p2-9.i386.rpm
File outdated by:  RHSA-2003:279
    d9fcc0d6d03c59b04681d6e755e3cb92
 

References


Keywords

IP, openssh, source


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/