From:	 tsl@trustix.com (Trustix Secure Linux Advisor)
To:	 tsl-announce@trustix.org
Subject: TSLSA-2002-0047 - openssh
Date:	 Mon, 29 Apr 2002 16:13:37 +0200

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Trustix Secure Linux Security Advisory #2002-0047

Package name:      openssh
Summary:           Minor security issue.
Date:              2002-04-29
Affected versions: TSL 1.1, 1.2, 1.5

- --------------------------------------------------------------------------

Problem description:
  When rebuilding the old openssh package with support for kerberos, one
  could potentially become vulnerable to a local root exploit. TSL is not
  shipped with Kerberos by default nor is the openssh packages compiled with
  kerberos support, but since we do expect some people to rebuild the src-rpm 
  with kerberos support enabled, we like to upgrade the package.

Action:
  We recommend that all systems with this package installed are upgraded.
  Please note that if you do not need the functionality provided by this
  package, you may want to remove it from your system.


Location:
  All TSL updates are available from
  <URI:http://www.trustix.net/pub/Trustix/updates/>
  <URI:ftp://ftp.trustix.net/pub/Trustix/updates/>


Automatic updates:
  Users of the SWUP tool can enjoy having updates automatically
  installed using 'swup --upgrade'.

  Get SWUP from:
  <URI:ftp://ftp.trustix.net/pub/Trustix/software/swup/>


Public testing:
  These packages have been available for public testing for some time.
  If you want to contribute by testing the various packages in the
  testing tree, please feel free to share your findings on the
  tsl-discuss mailinglist.
  The testing tree is located at
  <URI:http://www.trustix.net/pub/Trustix/testing/>
  <URI:ftp://ftp.trustix.net/pub/Trustix/testing/>
  

Questions?
  Check out our mailing lists:
  <URI:http://www.trustix.net/support/>


Verification:
  This advisory along with all TSL packages are signed with the TSL sign key.
  This key is available from:
  <URI:http://www.trustix.net/TSL-GPG-KEY>

  The advisory itself is available from the errata pages at
  <URI:http://www.trustix.net/errata/trustix-1.2/> and
  <URI:http://www.trustix.net/errata/trustix-1.5/>
  or directly at
  <URI:http://www.trustix.net/errata/misc/2002/TSL-2002-0047-openssh.asc.txt>


MD5sums of the packages:
- --------------------------------------------------------------------------
9d6b0684339eaf718b4a32495f786a62  ./1.5/SRPMS/openssh-3.1.0p1-3tr.src.rpm
f00b0fa1bf6f52826cf8623893501781  ./1.5/RPMS/openssh-server-3.1.0p1-3tr.i586.rpm
20a431fd990edfb51f62cf80c7298d82  ./1.5/RPMS/openssh-clients-3.1.0p1-3tr.i586.rpm
1c39ad2e73c23d6bcfbaf85766f341b6  ./1.5/RPMS/openssh-3.1.0p1-3tr.i586.rpm
9d6b0684339eaf718b4a32495f786a62  ./1.2/SRPMS/openssh-3.1.0p1-3tr.src.rpm
485e8bc57115a14bdd4b7fab5cea9fd4  ./1.2/RPMS/openssh-server-3.1.0p1-3tr.i586.rpm
5ca72211bea9a53858f7e815c4653efc  ./1.2/RPMS/openssh-clients-3.1.0p1-3tr.i586.rpm
d88579917fed5ee9b6a4da58a66c9cd0  ./1.2/RPMS/openssh-3.1.0p1-3tr.i586.rpm
9d6b0684339eaf718b4a32495f786a62  ./1.1/SRPMS/openssh-3.1.0p1-3tr.src.rpm
c72fe0dee9af01565bb352112ad1928b  ./1.1/RPMS/openssh-server-3.1.0p1-3tr.i586.rpm
e7d5808e75537a800fed61ff38c39f93  ./1.1/RPMS/openssh-clients-3.1.0p1-3tr.i586.rpm
733cda90f84e9d3e35dcb03ec035bf4b  ./1.1/RPMS/openssh-3.1.0p1-3tr.i586.rpm
- --------------------------------------------------------------------------


Trustix Security Team

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE8zTuFwRTcg4BxxS0RAvCeAJ9AU1n0cRA3X7uKUDpI8xJLp0bNRQCfbDrQ
c9hNPmhrnmckqqtBHULAinI=
=8YRS
-----END PGP SIGNATURE-----

_______________________________________________
tsl-announce mailing list
tsl-announce@trustix.org
http://www.trustix.org/mailman/listinfo.cgi/tsl-announce