Skip to navigation

Security Advisory openssh security update

Advisory: RHSA-2002:131-04
Type: Security Advisory
Severity: Moderate
Issued on: 2002-06-27
Last updated on: 2002-06-28
Affected Products: Red Hat Enterprise Linux AS (v. 2.1)
CVEs (cve.mitre.org): CVE-2002-0640

Details

Updated openssh packages are now available for Red Hat Linux Advanced
Server. These updates fix an input validation error in OpenSSH.

OpenSSH provides an implementation of the SSH (secure shell) protocol used
for logging into and executing commands on remote machines.

Versions of the OpenSSH server between 2.3.1 and 3.3 contain an input
validation error that can result in an integer overflow and privilege
escalation.

At this time, Red Hat does not believe that the default installation of
OpenSSH on Red Hat Linux is vulnerable to this issue; however a user would
be vulnerable if the configuration option "PAMAuthenticationViaKbdInt" is
enabled in the sshd configuration file (it is not enabled by default).

We have applied the security fix provided by the OpenSSH team to these
errata packages which are based on OpenSSH 3.1p1. This should minimize the
impact of upgrading to our errata packages.

All users of OpenSSH should update to these errata packages which are not
vulnerable to this issue.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

Please note that this update is available via Red Hat Network. To use Red
Hat Network, launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
openssh-3.1p1-6.src.rpm
File outdated by:  RHSA-2006:0698
    MD5: 84d1b32febbd22bcc76d44d3d985cf0d
 
IA-32:
openssh-3.1p1-6.i386.rpm
File outdated by:  RHSA-2006:0698
    MD5: a634222cd0d59ce1e9510323128fc34b
openssh-askpass-3.1p1-6.i386.rpm
File outdated by:  RHSA-2006:0698
    MD5: 1d84ecee0666441698fe7686c2f5ac3f
openssh-askpass-gnome-3.1p1-6.i386.rpm
File outdated by:  RHSA-2006:0698
    MD5: 7f568c333c7f15e2608b2adc134ad65a
openssh-clients-3.1p1-6.i386.rpm
File outdated by:  RHSA-2006:0698
    MD5: f7c7bcce4abd79c9604b0d43a7978cc1
openssh-server-3.1p1-6.i386.rpm
File outdated by:  RHSA-2006:0698
    MD5: c40ab32a22bac14625a845e342512785
 

References


Keywords

ChallengeResponseAuthentication, openssh, pam, security


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/