Oval Definition:oval:com.redhat.rhsa:def:20060044
Revision Date:2008-03-20Version:647
Title:RHSA-2006:0044: openssh security update (Low)
Description:OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. This package includes the core files necessary for both the OpenSSH client and server.

An arbitrary command execution flaw was discovered in the way scp copies files locally. It is possible for a local attacker to create a file with a carefully crafted name that could execute arbitrary commands as the user running scp to copy files locally. The Common Vulnerabilities and Exposures project (cve.mitre.org) assigned the name CVE-2006-0225 to this issue.

The following issue has also been fixed in this update:

If the sshd service was stopped using the sshd init script while the main sshd daemon was not running, the init script would kill other sshd processes, such as the running sessions. For example, this could happen when the 'service sshd stop' command was issued twice.

Additionally, this update implements auditing of user logins through the system audit service.

All users of openssh should upgrade to these updated packages, which resolve these issues.
Family:unixClass:patch
Status:Reference(s):CVE-2006-0225
RHSA-2006:0044
RHSA-2006:0044-02
RHSA-2006:0044-02
Platform(s):Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • openssh is earlier than 0:3.9p1-8.RHEL4.12
  • AND openssh is signed with Red Hat redhatrelease2 key
  • openssh-askpass is earlier than 0:3.9p1-8.RHEL4.12
  • AND openssh-askpass is signed with Red Hat redhatrelease2 key
  • openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.12
  • AND openssh-askpass-gnome is signed with Red Hat redhatrelease2 key
  • openssh-clients is earlier than 0:3.9p1-8.RHEL4.12
  • AND openssh-clients is signed with Red Hat redhatrelease2 key
  • openssh-server is earlier than 0:3.9p1-8.RHEL4.12
  • AND openssh-server is signed with Red Hat redhatrelease2 key
  • BACK