Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Debian Advisory for OpenSSH: Critical Access Exploit Severity High

debian
Calendar Grey March 8, 2002
Debian Logo
Debian Security Update highlighting OpenSSH flaws related to potential exploitation vulnerabilities that could lead to unauthorized access concerns.
Joost Pol reports that OpenSSH versions 2.0 through 3.0.2have an off-by-one bug in the channel allocation code

Summary

Joost Pol <joost@pine.nl> reports that OpenSSH versions 2.0 through 3.0.2
have an off-by-one bug in the channel allocation code. This vulnerability
can be exploited by authenticated users to gain root privilege or by a
malicious server exploiting a client with this bug.

Since Debian 2.2 (potato) shipped with OpenSSH (the "ssh" package)
version 1.2.3, it is not vulnerable to this exploit. No fix is required
for Debian 2.2 (potato).

The Debian unstable and testing archives do include a more recent OpenSSH
(ssh) package. If you are running these pre-release distributions you
should ensure that you are running version 3.0.2p1-8, a patched version
which was added to the unstable archive today, or a later version.

----------------------------------------------------------------------------
For apt-get: deb Debian -- Security Information stable/updates main
For dpkg-ftp: dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org





Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here