Bug 67509

Summary: OpenSSH vulnerablity disclosed on BugTraq
Product: [Retired] Red Hat Linux Reporter: Need Real Name <bgallia>
Component: opensshAssignee: Tomas Mraz <tmraz>
Status: CLOSED ERRATA QA Contact: Brian Brock <bbrock>
Severity: medium Docs Contact:
Priority: medium    
Version: 7.3CC: djuran, fisher, gdh, intrep
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2005-02-04 10:03:49 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Need Real Name 2002-06-26 18:05:38 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:0.9.9) Gecko/20020513

Description of problem:
ISS X-Force disclosed a bug that effects OpenSSH v2.9.9-3.3 if
UsePrivilegeSeparation is disabled.  This vulnerability has also been announced
on Slashdot.

Version-Release number of selected component (if applicable):


How reproducible:
Didn't try


Additional info:

I am seeking the following information:

Has Red hat tested enabling UsePrivilegeSeparation with
openssh-server-3.2.3p1-4.i386.rpm?

Is there any ETA for openssh v3.4 to be packaged?

Thanks

Comment 1 Mark J. Cox 2002-08-13 11:52:58 UTC
RHSA-2002:127 contained a backported security fix for the particular OpenSSH
vulnerability.