Bug 67464 - openssh security problem
openssh security problem
Product: Red Hat Linux
Classification: Retired
Component: openssh (Show other bugs)
i386 Linux
high Severity medium
: ---
: ---
Assigned To: Nalin Dahyabhai
Brian Brock
: Security
Depends On:
  Show dependency treegraph
Reported: 2002-06-25 15:02 EDT by flaps
Modified: 2007-03-26 23:54 EDT (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2002-06-25 15:02:34 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description flaps 2002-06-25 15:02:30 EDT
There is apparently a serious security bug in openssh, probably remote-root. 
See http://www.openssh.com .  Debian security fix URL was just posted to
bugtraq; it is http://www.debian.org/security/2002/dsa-134
They're not saying what the bug is yet, but the hush-hush suggests that it is

Also, it sure would be nice if you made it easier for those of us still running
some redhat 6.2 machines to upgrade to the new openssh you're presumably about
to release.  I guess you don't have any moral responsibility to because you
didn't distribute openssh with redhat 6.x, but I _think_ that merely a modern
openssl [that's an L] rpm for redhat 6.2, plus updated versions of everything
which depends upon openssl, would make the rest of it fairly easy for your
humble audience.  The big problem is some sort of incompatible change between
openssl 0.95 and 0.96, I think.

Comment 1 Mark J. Cox (Product Security) 2002-08-13 08:13:01 EDT

Note You need to log in before you can comment on or make changes to this bug.