Secunia Logo
 
Red Hat update for OpenSSH
Secunia Advisory: SA9747
Release Date: 2003-09-16
Last Update: 2003-09-18
Popularity: 9,049 views

Critical:
Highly critical
Impact: DoS
System access
Where: From remote
Solution Status: Vendor Patch

OS:RedHat Enterprise Linux AS 2.1
RedHat Enterprise Linux ES 2.1
RedHat Enterprise Linux WS 2.1
RedHat Linux 7.2
RedHat Linux 7.3
RedHat Linux 8.0
RedHat Linux 9
RedHat Linux Advanced Server 2.1 for Itanium
RedHat Linux Advanced Workstation 2.1 for Itanium

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2003-0682
CVE-2003-0693
CVE-2003-0695


Description:
Red Hat has issued updated packages to fix the "buffer_append_space()" vulnerability.

For more information see:
SA9743

Solution:
Packages for enterprise versions are only available via Red Hat Network.

Updated packages:

Red Hat Linux 7.1:

SRPMS:
ftp://updates.redhat.com/7.1/en/os/SRPMS/OpenSSH-3.1p1-13.src.rpm

i386:
ftp://updates.redhat.com/7.1/en/os/i386/OpenSSH-3.1p1-13.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/OpenSSH-clients-3.1p1-13.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/OpenSSH-server-3.1p1-13.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/OpenSSH-askpass-3.1p1-13.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/OpenSSH-askpass-gnome-3.1p1-13.i386.rpm

Red Hat Linux 7.2:

SRPMS:
ftp://updates.redhat.com/7.2/en/os/SRPMS/OpenSSH-3.1p1-14.src.rpm

i386:
ftp://updates.redhat.com/7.2/en/os/i386/OpenSSH-3.1p1-14.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/OpenSSH-clients-3.1p1-14.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/OpenSSH-server-3.1p1-14.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/OpenSSH-askpass-3.1p1-14.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/OpenSSH-askpass-gnome-3.1p1-14.i386.rpm

ia64:
ftp://updates.redhat.com/7.2/en/os/ia64/OpenSSH-3.1p1-14.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/OpenSSH-clients-3.1p1-14.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/OpenSSH-server-3.1p1-14.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/OpenSSH-askpass-3.1p1-14.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/OpenSSH-askpass-gnome-3.1p1-14.ia64.rpm

Red Hat Linux 7.3:

SRPMS:
ftp://updates.redhat.com/7.3/en/os/SRPMS/OpenSSH-3.1p1-14.src.rpm

i386:
ftp://updates.redhat.com/7.3/en/os/i386/OpenSSH-3.1p1-14.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/OpenSSH-clients-3.1p1-14.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/OpenSSH-server-3.1p1-14.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/OpenSSH-askpass-3.1p1-14.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/OpenSSH-askpass-gnome-3.1p1-14.i386.rpm

Red Hat Linux 8.0:

SRPMS:
ftp://updates.redhat.com/8.0/en/os/SRPMS/OpenSSH-3.4p1-7.src.rpm

i386:
ftp://updates.redhat.com/8.0/en/os/i386/OpenSSH-3.4p1-7.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/OpenSSH-clients-3.4p1-7.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/OpenSSH-server-3.4p1-7.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/OpenSSH-askpass-3.4p1-7.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/OpenSSH-askpass-gnome-3.4p1-7.i386.rpm

Red Hat Linux 9:

SRPMS:
ftp://updates.redhat.com/9/en/os/SRPMS/OpenSSH-3.5p1-11.src.rpm

i386:
ftp://updates.redhat.com/9/en/os/i386/OpenSSH-3.5p1-11.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/OpenSSH-clients-3.5p1-11.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/OpenSSH-server-3.5p1-11.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/OpenSSH-askpass-3.5p1-11.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/OpenSSH-askpass-gnome-3.5p1-11.i386.rpm

Red Hat Enterprise Linux AS (v. 2.1)
SRPMS:
openssh-3.1p1-14.src.rpm 2ffa9565705436314cf9b6dedcb30501

i386:
openssh-3.1p1-14.i386.rpm 621313655d8060a0454bd9ea24f2ecc4
openssh-askpass-3.1p1-14.i386.rpm 14c946af1e46502e65fd2a2e16e720af
openssh-askpass-gnome-3.1p1-14.i386.rpm 5d21951446986c2c9273b74bc6f24d42
openssh-clients-3.1p1-14.i386.rpm e60ebf607207738d0b06a634c872b51e
openssh-server-3.1p1-14.i386.rpm 36f8fcd31f88ddc370fdad1d05ab2faa

ia64:
openssh-3.1p1-14.ia64.rpm e05d229d860a745e3deb6919657608e1
openssh-askpass-3.1p1-14.ia64.rpm 40052191b71767409de985655a6ef15d
openssh-askpass-gnome-3.1p1-14.ia64.rpm f65ae2b19d3925c561e3f46a655e9933
openssh-clients-3.1p1-14.ia64.rpm 1559e98e2067218bc76a31fd92027386
openssh-server-3.1p1-14.ia64.rpm b2105a311ac26351368928af2e3573ca

Red Hat Enterprise Linux ES (v. 2.1)
SRPMS:
openssh-3.1p1-14.src.rpm 2ffa9565705436314cf9b6dedcb30501

i386:
openssh-3.1p1-14.i386.rpm 621313655d8060a0454bd9ea24f2ecc4
openssh-askpass-3.1p1-14.i386.rpm 14c946af1e46502e65fd2a2e16e720af
openssh-askpass-gnome-3.1p1-14.i386.rpm 5d21951446986c2c9273b74bc6f24d42
openssh-clients-3.1p1-14.i386.rpm e60ebf607207738d0b06a634c872b51e
openssh-server-3.1p1-14.i386.rpm 36f8fcd31f88ddc370fdad1d05ab2faa

Red Hat Enterprise Linux WS (v. 2.1)
SRPMS:
openssh-3.1p1-14.src.rpm 2ffa9565705436314cf9b6dedcb30501

i386:
openssh-3.1p1-14.i386.rpm 621313655d8060a0454bd9ea24f2ecc4
openssh-askpass-3.1p1-14.i386.rpm 14c946af1e46502e65fd2a2e16e720af
openssh-askpass-gnome-3.1p1-14.i386.rpm 5d21951446986c2c9273b74bc6f24d42
openssh-clients-3.1p1-14.i386.rpm e60ebf607207738d0b06a634c872b51e
openssh-server-3.1p1-14.i386.rpm 36f8fcd31f88ddc370fdad1d05ab2faa

Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
SRPMS:
openssh-3.1p1-14.src.rpm 2ffa9565705436314cf9b6dedcb30501

ia64:
openssh-3.1p1-14.ia64.rpm e05d229d860a745e3deb6919657608e1
openssh-askpass-3.1p1-14.ia64.rpm 40052191b71767409de985655a6ef15d
openssh-askpass-gnome-3.1p1-14.ia64.rpm f65ae2b19d3925c561e3f46a655e9933
openssh-clients-3.1p1-14.ia64.rpm 1559e98e2067218bc76a31fd92027386
openssh-server-3.1p1-14.ia64.rpm b2105a311ac26351368928af2e3573ca

Changelog:
2003-09-18: Updated advisory with information about new packages which also fixes CAN-2003-0682 and CAN-2003-0695.

Original Advisory:
http://rhn.redhat.com/errata/RHSA-2003-279.html
http://rhn.redhat.com/errata/RHSA-2003-280.html

Other References:
SA9743:
http://secunia.com/advisories/9743/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 152 views
2. Adobe Flash Player Multiple Security Issues and Vulnerabilities // 93 views
3. VLC Media Player Real Demuxer Integer Overflow Vulnerability // 71 views
4. VMware ESX / ESXi Virtual Hardware Memory Corruption Vulnerability // 58 views
5. SquirrelMail Malformed HTML Mail Message Script Insertion // 54 views
6. mvnForum Unspecified Cross-Site Scripting and Request Forgery // 43 views
7. VMware ESX Server update for bzip2 // 38 views
8. Mozilla Firefox 3 Multiple Vulnerabilities // 37 views
9. Movable Type Unspecified Cross-Site Scripting Vulnerability // 37 views
10. Sunbyte e-Flower "id" SQL Injection Vulnerability // 36 views