Oval Definition:oval:com.redhat.rhsa:def:20070257
Revision Date:2008-03-20Version:640
Title:RHSA-2007:0257: openssh security and bug fix update (Low)
Description:OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. This package includes the core files necessary for both the OpenSSH client and server.

  • OpenSSH stores hostnames, IP addresses, and keys in plaintext in the known_hosts file. A local attacker that has already compromised a user's SSH account could use this information to generate a list of additional targets that are likely to have the same password or key. (CVE-2005-2666)

    The following bugs have also been fixed in this update:

    The ssh client could abort the running connection when the server application generated a large output at once.

    When 'X11UseLocalhost' option was set to 'no' on systems with IPv6 networking enabled, the X11 forwarding socket listened only for IPv6 connections.

    When the privilege separation was enabled in /etc/ssh/sshd_config, some log messages in the system log were duplicated and also had timestamps from an incorrect timezone.

    All users of openssh should upgrade to these updated packages, which contain backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2005-2666
    RHSA-2007:0257
    RHSA-2007:0257-02
    RHSA-2007:0257-02
    Platform(s):Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • openssh is earlier than 0:3.9p1-8.RHEL4.20
  • AND openssh is signed with Red Hat redhatrelease2 key
  • openssh-askpass is earlier than 0:3.9p1-8.RHEL4.20
  • AND openssh-askpass is signed with Red Hat redhatrelease2 key
  • openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.20
  • AND openssh-askpass-gnome is signed with Red Hat redhatrelease2 key
  • openssh-clients is earlier than 0:3.9p1-8.RHEL4.20
  • AND openssh-clients is signed with Red Hat redhatrelease2 key
  • openssh-server is earlier than 0:3.9p1-8.RHEL4.20
  • AND openssh-server is signed with Red Hat redhatrelease2 key
  • BACK