Updated OpenSSH packages are now available for Red Hat Linux 7, 7.1, and
7.2. These updates fix a bug in handling of restricted keys which may
allow users to bypass command restrictions by using subsystems and a subtle
bug which might aid a passive analysis attack.
OpenSSH versions prior to 2.9.9, when configured to provide sftp access
using the subsystem feature, allows remote authenticated users to bypass
authorized_keys2 "command=" restrictions by using sftp commands.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2001-0816 to this issue.
OpenSSH 2.9 also contained a subtle bug in the routines which attempt to
confound an attacker using passive analysis, which would cause it to send
two confounding packets instead of one when a client finished sending it a
password.
Red Hat would like to thank Solar Designer and Markus Friedl for assisting
with the patches.
| Red Hat Linux 7.0 |
|
| SRPMS: |
openssh-2.9p2-10.7.src.rpm
File outdated by: RHSA-2002:127 |
6aaf629a210dea1988e7631e60072681 |
| |
| Alpha: |
openssh-2.9p2-10.7.alpha.rpm
File outdated by: RHSA-2002:127 |
340e97c4aa1b88cb83b29929d2031a8b |
openssh-askpass-2.9p2-10.7.alpha.rpm
File outdated by: RHSA-2002:127 |
833c1efcc3f0b501b2f95dc0225a1110 |
openssh-askpass-gnome-2.9p2-10.7.alpha.rpm
File outdated by: RHSA-2002:127 |
6afbdb015d3ae72cf34c5005212ce14d |
openssh-clients-2.9p2-10.7.alpha.rpm
File outdated by: RHSA-2002:127 |
890b6a4623bd251cbb509e0f52976aa8 |
openssh-server-2.9p2-10.7.alpha.rpm
File outdated by: RHSA-2002:127 |
38dcfb8105a2585eb66166509ffb8ec3 |
| |
| IA-32: |
openssh-2.9p2-10.7.i386.rpm
File outdated by: RHSA-2002:127 |
206678dd9fed4e895282fdf944026fd5 |
openssh-askpass-2.9p2-10.7.i386.rpm
File outdated by: RHSA-2002:127 |
932b8383849cd3c72575026873e04b2a |
openssh-askpass-gnome-2.9p2-10.7.i386.rpm
File outdated by: RHSA-2002:127 |
451ad9f475a4816b7def9f4737a2910f |
openssh-clients-2.9p2-10.7.i386.rpm
File outdated by: RHSA-2002:127 |
e6aaa5454932133eb5140d5aa8694c23 |
openssh-server-2.9p2-10.7.i386.rpm
File outdated by: RHSA-2002:127 |
2e2c50953866c77510e320587b2b763a |
| |
| Red Hat Linux 7.1 |
|
| SRPMS: |
openssh-2.9p2-10.7.src.rpm
File outdated by: RHSA-2002:127 |
6aaf629a210dea1988e7631e60072681 |
| |
| Alpha: |
openssh-2.9p2-10.7.alpha.rpm
File outdated by: RHSA-2002:127 |
340e97c4aa1b88cb83b29929d2031a8b |
openssh-askpass-2.9p2-10.7.alpha.rpm
File outdated by: RHSA-2002:127 |
833c1efcc3f0b501b2f95dc0225a1110 |
openssh-askpass-gnome-2.9p2-10.7.alpha.rpm
File outdated by: RHSA-2002:127 |
6afbdb015d3ae72cf34c5005212ce14d |
openssh-clients-2.9p2-10.7.alpha.rpm
File outdated by: RHSA-2002:127 |
890b6a4623bd251cbb509e0f52976aa8 |
openssh-server-2.9p2-10.7.alpha.rpm
File outdated by: RHSA-2002:127 |
38dcfb8105a2585eb66166509ffb8ec3 |
| |
| IA-32: |
openssh-2.9p2-10.7.i386.rpm
File outdated by: RHSA-2003:279 |
206678dd9fed4e895282fdf944026fd5 |
openssh-askpass-2.9p2-10.7.i386.rpm
File outdated by: RHSA-2003:279 |
932b8383849cd3c72575026873e04b2a |
openssh-askpass-gnome-2.9p2-10.7.i386.rpm
File outdated by: RHSA-2003:279 |
451ad9f475a4816b7def9f4737a2910f |
openssh-clients-2.9p2-10.7.i386.rpm
File outdated by: RHSA-2003:279 |
e6aaa5454932133eb5140d5aa8694c23 |
openssh-server-2.9p2-10.7.i386.rpm
File outdated by: RHSA-2003:279 |
2e2c50953866c77510e320587b2b763a |
| |
| IA-64: |
openssh-2.9p2-10.7.ia64.rpm
File outdated by: RHSA-2002:127 |
40f477635b6440dfd46afe59e28bf8f9 |
openssh-askpass-2.9p2-10.7.ia64.rpm
File outdated by: RHSA-2002:127 |
702b0a6703da90a7cca6037f6947794f |
openssh-askpass-gnome-2.9p2-10.7.ia64.rpm
File outdated by: RHSA-2002:127 |
60f72ff95c7c3d41b56b3cb969e6494e |
openssh-clients-2.9p2-10.7.ia64.rpm
File outdated by: RHSA-2002:127 |
5c4e3ae0ce17e742b8dc3acd807246ec |
openssh-server-2.9p2-10.7.ia64.rpm
File outdated by: RHSA-2002:127 |
3400b7fb0337971f652a1e6403fb234d |
| |
| Red Hat Linux 7.2 |
|
| SRPMS: |
openssh-2.9p2-11.src.rpm
File outdated by: RHSA-2003:279 |
90ce862375e8410ed5c5a29d9f23ed63 |
| |
| IA-32: |
openssh-2.9p2-11.i386.rpm
File outdated by: RHSA-2003:279 |
ee061bdb5d9907ae65259c60823545db |
openssh-askpass-2.9p2-11.i386.rpm
File outdated by: RHSA-2003:279 |
8f589e90d818865053666bcfeed32bdb |
openssh-askpass-gnome-2.9p2-11.i386.rpm
File outdated by: RHSA-2003:279 |
3233cdafc1f62b926414b05445415548 |
openssh-clients-2.9p2-11.i386.rpm
File outdated by: RHSA-2003:279 |
3b7ef488182ae3afbd639e74e7eed8cc |
openssh-server-2.9p2-11.i386.rpm
File outdated by: RHSA-2003:279 |
3358900ffa3d3327c9cfe79b365c1464 |
| |