Oval Definition:oval:com.redhat.rhsa:def:20060697
Revision Date:2008-03-20Version:642
Title:RHSA-2006:0697: openssh security update (Important)
Description:OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. This package includes the core files necessary for both the OpenSSH client and server.

Mark Dowd discovered a signal handler race condition in the OpenSSH sshd server. A remote attacker could possibly leverage this flaw to cause a denial of service (crash). (CVE-2006-5051) The OpenSSH project believes the likelihood of successful exploitation leading to arbitrary code execution appears remote. However, the Red Hat Security Response Team have not yet been able to verify this claim due to lack of upstream vulnerability information. We are therefore including a fix for this flaw and have rated it important security severity in the event our continued investigation finds this issue to be exploitable.

  • Tavis Ormandy of the Google Security Team discovered a denial of service bug in the OpenSSH sshd server. A remote attacker can send a specially crafted SSH-1 request to the server causing sshd to consume a large quantity of CPU resources. (CVE-2006-4924)

    All users of openssh should upgrade to these updated packages, which contain backported patches that resolves these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2006-4924
    CVE-2006-5051
    RHSA-2006:0697
    RHSA-2006:0697-01
    RHSA-2006:0697-01
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • openssh-clients is earlier than 0:3.6.1p2-33.30.12
  • AND openssh-clients is signed with Red Hat master key
  • openssh-askpass-gnome is earlier than 0:3.6.1p2-33.30.12
  • AND openssh-askpass-gnome is signed with Red Hat master key
  • openssh-askpass is earlier than 0:3.6.1p2-33.30.12
  • AND openssh-askpass is signed with Red Hat master key
  • openssh-server is earlier than 0:3.6.1p2-33.30.12
  • AND openssh-server is signed with Red Hat master key
  • openssh is earlier than 0:3.6.1p2-33.30.12
  • AND openssh is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • openssh-server is earlier than 0:3.9p1-8.RHEL4.17
  • AND openssh-server is signed with Red Hat master key
  • openssh-askpass is earlier than 0:3.9p1-8.RHEL4.17
  • AND openssh-askpass is signed with Red Hat master key
  • openssh is earlier than 0:3.9p1-8.RHEL4.17
  • AND openssh is signed with Red Hat master key
  • openssh-clients is earlier than 0:3.9p1-8.RHEL4.17
  • AND openssh-clients is signed with Red Hat master key
  • openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.17
  • AND openssh-askpass-gnome is signed with Red Hat master key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • openssh is earlier than 0:3.6.1p2-33.30.12
  • AND openssh is signed with Red Hat master key
  • openssh-askpass is earlier than 0:3.6.1p2-33.30.12
  • AND openssh-askpass is signed with Red Hat master key
  • openssh-askpass-gnome is earlier than 0:3.6.1p2-33.30.12
  • AND openssh-askpass-gnome is signed with Red Hat master key
  • openssh-clients is earlier than 0:3.6.1p2-33.30.12
  • AND openssh-clients is signed with Red Hat master key
  • openssh-server is earlier than 0:3.6.1p2-33.30.12
  • AND openssh-server is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • openssh is earlier than 0:3.9p1-8.RHEL4.17
  • AND openssh is signed with Red Hat master key
  • openssh-askpass is earlier than 0:3.9p1-8.RHEL4.17
  • AND openssh-askpass is signed with Red Hat master key
  • openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.17
  • AND openssh-askpass-gnome is signed with Red Hat master key
  • openssh-clients is earlier than 0:3.9p1-8.RHEL4.17
  • AND openssh-clients is signed with Red Hat master key
  • openssh-server is earlier than 0:3.9p1-8.RHEL4.17
  • AND openssh-server is signed with Red Hat master key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • openssh is earlier than 0:3.9p1-8.RHEL4.17
  • AND openssh is signed with Red Hat redhatrelease2 key
  • openssh-askpass is earlier than 0:3.9p1-8.RHEL4.17
  • AND openssh-askpass is signed with Red Hat redhatrelease2 key
  • openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.17
  • AND openssh-askpass-gnome is signed with Red Hat redhatrelease2 key
  • openssh-clients is earlier than 0:3.9p1-8.RHEL4.17
  • AND openssh-clients is signed with Red Hat redhatrelease2 key
  • openssh-server is earlier than 0:3.9p1-8.RHEL4.17
  • AND openssh-server is signed with Red Hat redhatrelease2 key
  • BACK