Oval Definition:oval:com.redhat.rhsa:def:20060738
Revision Date:2006-11-15Version:637
Title:RHSA-2006:0738: openssh security update (Low)
Description:OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. This package includes the core files necessary for both the OpenSSH client and server.

  • An authentication flaw was found in OpenSSH's privilege separation monitor. If it ever becomes possible to alter the behavior of the unprivileged process when OpenSSH is using privilege separation, an attacker may then be able to login without possessing proper credentials. (CVE-2006-5794)

    Please note that this flaw by itself poses no direct threat to OpenSSH users. Without another security flaw that could allow an attacker to alter the behavior of OpenSSH's unprivileged process, this flaw cannot be exploited. There are currently no known flaws to exploit this behavior. However, we have decided to issue this erratum to fix this flaw to reduce the security impact if an unprivileged process flaw is ever found.

    Users of openssh should upgrade to these updated packages, which contain a backported patch to resolve this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2006-5794
    RHSA-2006:0738
    RHSA-2006:0738-01
    RHSA-2006:0738-01
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • openssh-clients is earlier than 0:3.6.1p2-33.30.13
  • AND openssh-clients is signed with Red Hat master key
  • openssh-askpass-gnome is earlier than 0:3.6.1p2-33.30.13
  • AND openssh-askpass-gnome is signed with Red Hat master key
  • openssh-askpass is earlier than 0:3.6.1p2-33.30.13
  • AND openssh-askpass is signed with Red Hat master key
  • openssh-server is earlier than 0:3.6.1p2-33.30.13
  • AND openssh-server is signed with Red Hat master key
  • openssh is earlier than 0:3.6.1p2-33.30.13
  • AND openssh is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • openssh-server is earlier than 0:3.9p1-8.RHEL4.17.1
  • AND openssh-server is signed with Red Hat master key
  • openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.17.1
  • AND openssh-askpass-gnome is signed with Red Hat master key
  • openssh-clients is earlier than 0:3.9p1-8.RHEL4.17.1
  • AND openssh-clients is signed with Red Hat master key
  • openssh-askpass is earlier than 0:3.9p1-8.RHEL4.17.1
  • AND openssh-askpass is signed with Red Hat master key
  • openssh is earlier than 0:3.9p1-8.RHEL4.17.1
  • AND openssh is signed with Red Hat master key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • openssh is earlier than 0:3.6.1p2-33.30.13
  • AND openssh is signed with Red Hat master key
  • openssh-askpass is earlier than 0:3.6.1p2-33.30.13
  • AND openssh-askpass is signed with Red Hat master key
  • openssh-askpass-gnome is earlier than 0:3.6.1p2-33.30.13
  • AND openssh-askpass-gnome is signed with Red Hat master key
  • openssh-clients is earlier than 0:3.6.1p2-33.30.13
  • AND openssh-clients is signed with Red Hat master key
  • openssh-server is earlier than 0:3.6.1p2-33.30.13
  • AND openssh-server is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • openssh is earlier than 0:3.9p1-8.RHEL4.17.1
  • AND openssh is signed with Red Hat master key
  • openssh-askpass is earlier than 0:3.9p1-8.RHEL4.17.1
  • AND openssh-askpass is signed with Red Hat master key
  • openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.17.1
  • AND openssh-askpass-gnome is signed with Red Hat master key
  • openssh-clients is earlier than 0:3.9p1-8.RHEL4.17.1
  • AND openssh-clients is signed with Red Hat master key
  • openssh-server is earlier than 0:3.9p1-8.RHEL4.17.1
  • AND openssh-server is signed with Red Hat master key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • openssh is earlier than 0:3.9p1-8.RHEL4.17.1
  • AND openssh is signed with Red Hat redhatrelease2 key
  • openssh-askpass is earlier than 0:3.9p1-8.RHEL4.17.1
  • AND openssh-askpass is signed with Red Hat redhatrelease2 key
  • openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.17.1
  • AND openssh-askpass-gnome is signed with Red Hat redhatrelease2 key
  • openssh-clients is earlier than 0:3.9p1-8.RHEL4.17.1
  • AND openssh-clients is signed with Red Hat redhatrelease2 key
  • openssh-server is earlier than 0:3.9p1-8.RHEL4.17.1
  • AND openssh-server is signed with Red Hat redhatrelease2 key
  • BACK