Bug 67509 - OpenSSH vulnerablity disclosed on BugTraq
OpenSSH vulnerablity disclosed on BugTraq
Status: CLOSED ERRATA
Product: Red Hat Linux
Classification: Retired
Component: openssh (Show other bugs)
7.3
All Linux
medium Severity medium
: ---
: ---
Assigned To: Tomas Mraz
Brian Brock
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2002-06-26 14:05 EDT by Need Real Name
Modified: 2007-04-18 12:43 EDT (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2005-02-04 05:03:49 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Need Real Name 2002-06-26 14:05:38 EDT
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:0.9.9) Gecko/20020513

Description of problem:
ISS X-Force disclosed a bug that effects OpenSSH v2.9.9-3.3 if
UsePrivilegeSeparation is disabled.  This vulnerability has also been announced
on Slashdot.

Version-Release number of selected component (if applicable):


How reproducible:
Didn't try


Additional info:

I am seeking the following information:

Has Red hat tested enabling UsePrivilegeSeparation with
openssh-server-3.2.3p1-4.i386.rpm?

Is there any ETA for openssh v3.4 to be packaged?

Thanks
Comment 1 Mark J. Cox (Product Security) 2002-08-13 07:52:58 EDT
RHSA-2002:127 contained a backported security fix for the particular OpenSSH
vulnerability.

Note You need to log in before you can comment on or make changes to this bug.