make money Powered LINK: Ubuntu security announce: OpenSSH vulnerability (Kees Cook)

Wednesday, January 23, 2008

Ubuntu security announce: OpenSSH vulnerability (Kees Cook)

A security issue affects the following Ubuntu releases:

  • Ubuntu 6.06 LTS
  • Ubuntu 6.10
  • Ubuntu 7.04
  • Ubuntu 7.10

This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the following package versions:

  • Ubuntu 6.06 LTS: openssh-client 1:4.2p1-7ubuntu3.2
  • Ubuntu 6.10: openssh-client 1:4.3p2-5ubuntu1.1
  • Ubuntu 7.04: openssh-client 1:4.3p2-8ubuntu1.1
  • Ubuntu 7.10: openssh-client 1:4.6p1-5ubuntu0.1

In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:
Jan Pechanec discovered that ssh would forward trusted X11 cookies when untrusted cookie generation failed. This could lead to unintended privileges being forwarded to a remote host.
more
source:windows-center.blogspot.com

No comments: