Security Advisory openssh security update

Advisory: RHSA-2003:224-07
Type: Security Advisory
Severity: Low
Issued on: 2003-07-29
Last updated on: 2003-07-29
Affected Products: Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux WS (v. 2.1)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
OVAL: N/A
CVEs (cve.mitre.org): CVE-2003-0190

Details

Updated OpenSSH packages are now available. These updates close an
information leak caused by sshd's interaction with the PAM system.

OpenSSH is a suite of network connectivity tools that can be used to
establish encrypted connections between systems on a network and can
provide interactive login sessions and port forwarding, among other functions.

When configured to allow password-based or challenge-response
authentication, sshd (the OpenSSH server) uses PAM (Pluggable
Authentication Modules) to verify the user's password. Under certain
conditions, OpenSSH versions prior to 3.6.1p1 reject an invalid
authentication attempt without first attempting authentication using PAM.

If PAM is configured with its default failure delay, the amount of time
sshd takes to reject an invalid authentication request varies widely enough
that the timing variations could be used to deduce whether or not an
account with a specified name existed on the server. This information
could then be used to narrow the focus of an attack against some other
system component.

These updates contain backported fixes that cause sshd to always attempt
PAM authentication when performing password and challenge-response
authentication for clients.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
openssh-3.1p1-8.src.rpm     22f17a835f12a4131a21487d5ee3dec6
 
IA-32:
openssh-3.1p1-8.i386.rpm
File outdated by:  RHSA-2006:0698
    013694ec0e839f077e7980d9cebfa277
openssh-askpass-3.1p1-8.i386.rpm
File outdated by:  RHSA-2006:0698
    a942a051510a5a0aa34b0774d6eb8ee0
openssh-askpass-gnome-3.1p1-8.i386.rpm
File outdated by:  RHSA-2006:0698
    de35a67fa21ec478aff57ce5c830f84e
openssh-clients-3.1p1-8.i386.rpm
File outdated by:  RHSA-2006:0698
    8c9d37f46f76093eccea80571d687d46
openssh-server-3.1p1-8.i386.rpm
File outdated by:  RHSA-2006:0698
    42ec08d8633862da9c988524fecdafbb
 
IA-64:
openssh-3.1p1-8.ia64.rpm
File outdated by:  RHSA-2006:0698
    d9441bbe925832b82766b8140fb4bb77
openssh-askpass-3.1p1-8.ia64.rpm
File outdated by:  RHSA-2006:0698
    58765b526317e03dcf9371d9b225fa68
openssh-askpass-gnome-3.1p1-8.ia64.rpm
File outdated by:  RHSA-2006:0698
    46b8de0e5072ff7ee614c7e5dfc536b9
openssh-clients-3.1p1-8.ia64.rpm
File outdated by:  RHSA-2006:0698
    1e95e8ca735b971bcb1a1824becaa582
openssh-server-3.1p1-8.ia64.rpm
File outdated by:  RHSA-2006:0698
    8ae51f6f0116f60fd29545b4f9560613
 
Red Hat Enterprise Linux ES (v. 2.1)

SRPMS:
openssh-3.1p1-8.src.rpm     22f17a835f12a4131a21487d5ee3dec6
 
IA-32:
openssh-3.1p1-8.i386.rpm
File outdated by:  RHSA-2006:0698
    013694ec0e839f077e7980d9cebfa277
openssh-askpass-3.1p1-8.i386.rpm
File outdated by:  RHSA-2006:0698
    a942a051510a5a0aa34b0774d6eb8ee0
openssh-askpass-gnome-3.1p1-8.i386.rpm
File outdated by:  RHSA-2006:0698
    de35a67fa21ec478aff57ce5c830f84e
openssh-clients-3.1p1-8.i386.rpm
File outdated by:  RHSA-2006:0698
    8c9d37f46f76093eccea80571d687d46
openssh-server-3.1p1-8.i386.rpm
File outdated by:  RHSA-2006:0698
    42ec08d8633862da9c988524fecdafbb
 
Red Hat Enterprise Linux WS (v. 2.1)

SRPMS:
openssh-3.1p1-8.src.rpm     22f17a835f12a4131a21487d5ee3dec6
 
IA-32:
openssh-3.1p1-8.i386.rpm
File outdated by:  RHSA-2006:0698
    013694ec0e839f077e7980d9cebfa277
openssh-askpass-3.1p1-8.i386.rpm
File outdated by:  RHSA-2006:0698
    a942a051510a5a0aa34b0774d6eb8ee0
openssh-askpass-gnome-3.1p1-8.i386.rpm
File outdated by:  RHSA-2006:0698
    de35a67fa21ec478aff57ce5c830f84e
openssh-clients-3.1p1-8.i386.rpm
File outdated by:  RHSA-2006:0698
    8c9d37f46f76093eccea80571d687d46
openssh-server-3.1p1-8.i386.rpm
File outdated by:  RHSA-2006:0698
    42ec08d8633862da9c988524fecdafbb
 
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor

SRPMS:
openssh-3.1p1-8.src.rpm     22f17a835f12a4131a21487d5ee3dec6
 
IA-64:
openssh-3.1p1-8.ia64.rpm
File outdated by:  RHSA-2006:0698
    d9441bbe925832b82766b8140fb4bb77
openssh-askpass-3.1p1-8.ia64.rpm
File outdated by:  RHSA-2006:0698
    58765b526317e03dcf9371d9b225fa68
openssh-askpass-gnome-3.1p1-8.ia64.rpm
File outdated by:  RHSA-2006:0698
    46b8de0e5072ff7ee614c7e5dfc536b9
openssh-clients-3.1p1-8.ia64.rpm
File outdated by:  RHSA-2006:0698
    1e95e8ca735b971bcb1a1824becaa582
openssh-server-3.1p1-8.ia64.rpm
File outdated by:  RHSA-2006:0698
    8ae51f6f0116f60fd29545b4f9560613
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

98594 - CAN-2003-0190 OpenSSH valid username information leak


References


Keywords

information, leak, openssh, pam, timing


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/