From:	 tsl@trustix.com (Trustix Secure Linux Advisor)
To:	 tsl-announce@trustix.org
Subject: TSLSA-2002-0039 - openssh
Date:	 Fri, 8 Mar 2002 17:15:13 +0100
Cc:	 bugtraq@securityfocus.com, linsec@lists.seifried.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Trustix Secure Linux Security Advisory #2002-0039

Package name:      openssh
Summary:           Version upgrade security fix
Date:              2002-03-07
Affected versions: TSL 1.1, 1.2, 1.5

- --------------------------------------------------------------------------

Problem description:
  Users with an existing user account could potentially abuse a bug 
  to in the channel code and gain root privileges. Exploitability without an 
  existing user account has not been proven but is not considered impossible.


Action:
  We recommend that all systems with this package installed are upgraded.
  Please note that if you do not need the functionality provided by this
  package, you may want to remove it from your system.


Location:
  All TSL updates are available from
  <URI:http://www.trustix.net/pub/Trustix/updates/>
  <URI:ftp://ftp.trustix.net/pub/Trustix/updates/>


Automatic updates:
  Users of the SWUP tool can enjoy having updates automatically
  installed using 'swup --upgrade'.

  Get SWUP from:
  <URI:ftp://ftp.trustix.net/pub/Trustix/software/swup/>


Public testing:
  These packages have been available for public testing for some time.
  If you want to contribute by testing the various packages in the
  testing tree, please feel free to share your findings on the
  tsl-discuss mailinglist.
  The testing tree is located at
  <URI:http://www.trustix.net/pub/Trustix/testing/>
  <URI:ftp://ftp.trustix.net/pub/Trustix/testing/>
  

Questions?
  Check out our mailing lists:
  <URI:http://www.trustix.net/support/>


Verification:
  This advisory along with all TSL packages are signed with the TSL sign key.
  This key is available from:
  <URI:http://www.trustix.net/TSL-GPG-KEY>

  The advisory itself is available from the errata pages at
  <URI:http://www.trustix.net/errata/trustix-1.2/> and
  <URI:http://www.trustix.net/errata/trustix-1.5/>
  or directly at
  <URI:http://www.trustix.net/errata/misc/2002/TSL-2002-0039-default.asc.txt>


MD5sums of the packages:
- --------------------------------------------------------------------------
9e1e15c8b4dce51f6158445d19c3b82e  ./1.5/SRPMS/openssh-3.1.0p1-1tr.src.rpm
ea1ce72d57e85fd802254ea760be2381  ./1.5/RPMS/openssh-server-3.1.0p1-1tr.i586.rpm
4692b3ac3cf452f0b0b0d00312befdce  ./1.5/RPMS/openssh-clients-3.1.0p1-1tr.i586.rpm
e9ca3b690ee49b0c6b85586b69b94b1c  ./1.5/RPMS/openssh-3.1.0p1-1tr.i586.rpm
9e1e15c8b4dce51f6158445d19c3b82e  ./1.2/SRPMS/openssh-3.1.0p1-1tr.src.rpm
912d7dee5c77776273d4a6575310c42c  ./1.2/RPMS/openssh-server-3.1.0p1-1tr.i586.rpm
6fd3a02182797cd64a6d97c03ec68780  ./1.2/RPMS/openssh-clients-3.1.0p1-1tr.i586.rpm
b14bfb5a6d1c28f087a63afdd93cf10a  ./1.2/RPMS/openssh-3.1.0p1-1tr.i586.rpm
9e1e15c8b4dce51f6158445d19c3b82e  ./1.1/SRPMS/openssh-3.1.0p1-1tr.src.rpm
dc5f36291b4b74d8106fe2de6e2c74a3  ./1.1/RPMS/openssh-server-3.1.0p1-1tr.i586.rpm
0ae4711f02c3c83c978758f8a79f1da4  ./1.1/RPMS/openssh-clients-3.1.0p1-1tr.i586.rpm
b458a0887b8cfde9e700ace3dd37a521  ./1.1/RPMS/openssh-3.1.0p1-1tr.i586.rpm
- --------------------------------------------------------------------------


Trustix Security Team

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE8h5v/wRTcg4BxxS0RAnk3AJ4769VvnRQnQhkLx9jDfdj3YFB1RQCdFLQg
EPQvB1NQNeNMnPgtbRjndlQ=
=870B
-----END PGP SIGNATURE-----

_______________________________________________
tsl-announce mailing list
tsl-announce@trustix.org
http://www.trustix.org/mailman/listinfo.cgi/tsl-announce