Secunia Logo
 
SuSE update for OpenSSH
Secunia Advisory: SA9750
Release Date: 2003-09-17
Last Update: 2003-09-19
Popularity: 6,925 views

Critical:
Highly critical
Impact: DoS
System access
Where: From remote
Solution Status: Vendor Patch

OS:SuSE eMail Server 3.x
SuSE Linux 7.x
SuSE Linux 8.x
SuSE Linux Connectivity Server
SuSE Linux Database Server
SuSE Linux Enterprise Server 7
SuSE Linux Enterprise Server 8
SuSE Linux Firewall on CD/Admin host
SuSE Linux Office Server

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2003-0693
CVE-2003-0695
CVE-2003-0682


Description:
SuSE has issued updated packages for ssh. These fix a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

For more information:
SA9743

Solution:
Updated packages:

Intel i386 Platform:

SuSE-8.2:
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/openssh-3.5p1-107.i586.rpm
e030b0803481d0f29f576e3b4726284f
patch rpm(s):
ftp://ftp.suse.com/pub/suse/i386/upda...i586/openssh-3.5p1-107.i586.patch.rpm
d022894363b99e6bd03e9b2109c2244c
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/src/openssh-3.5p1-107.src.rpm
3f7f5ed43c7d795c63fe06148874944a

SuSE-8.1:
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/openssh-3.4p1-215.i586.rpm
91cdd33a4149756b8f6371aa3177a5f4
patch rpm(s):
ftp://ftp.suse.com/pub/suse/i386/upda...i586/openssh-3.4p1-215.i586.patch.rpm
3b7c44819c8fed5e33514481d99d4ab7
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/src/openssh-3.4p1-215.src.rpm
6c3694fc75bcf185035547b85abbc491

SuSE-8.0:
ftp://ftp.suse.com/pub/suse/i386/update/8.0/sec1/openssh-3.4p1-215.i386.rpm
c61781b97767188cc3a39795535307ff
patch rpm(s):
ftp://ftp.suse.com/pub/suse/i386/upda...sec1/openssh-3.4p1-215.i386.patch.rpm
c222aef79a8fef6d44d8d61fc075efc5
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/8.0/zq1/openssh-3.4p1-215.src.rpm
bc327a4150058c9d1216cb96712973a5

SuSE-7.3:
ftp://ftp.suse.com/pub/suse/i386/update/7.3/sec1/openssh-2.9.9p2-156.i386.rpm
c9928c04b03cb292aa96ad6890a5ee38
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/7.3/zq1/openssh-2.9.9p2-156.src.rpm
28aa82be9233e3ba93b94eb138c9ea04

SuSE-7.2:
ftp://ftp.suse.com/pub/suse/i386/update/7.2/sec1/openssh-2.9.9p2-156.i386.rpm
b369724a788a2c6bd70a448a49530f69
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/7.2/zq1/openssh-2.9.9p2-156.src.rpm
98b8b7281fe04aab8c8838adcf195697

Sparc Platform:

SuSE-7.3:
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/sec1/openssh-2.9.9p2-53.sparc.rpm
97cb0218e9354b8cc062e44a0d6fb19f
source rpm(s):
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/zq1/openssh-2.9.9p2-53.src.rpm
8cddb96e633864469d7ba08d3cf7436a

PPC Power PC Platform:

SuSE-7.3:
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/sec1/openssh-2.9.9p2-109.ppc.rpm
37b1e82a3971f5c4c427ce37227b11e0
source rpm(s):
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/zq1/openssh-2.9.9p2-109.src.rpm
7a19424887772b86d14bacbf5add9628

Changelog:
2003-09-19: Updated advisory with information about new packages which also fixes CAN-2003-0682 and CAN-2003-0695.

Other References:
SA9743:
http://secunia.com/advisories/9743/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 152 views
2. Adobe Flash Player Multiple Security Issues and Vulnerabilities // 84 views
3. VLC Media Player Real Demuxer Integer Overflow Vulnerability // 81 views
4. VMware ESX / ESXi Virtual Hardware Memory Corruption Vulnerability // 59 views
5. VMware ESX Server update for bzip2 // 47 views
6. SquirrelMail Malformed HTML Mail Message Script Insertion // 43 views
7. Mozilla Firefox 3 Multiple Vulnerabilities // 36 views
8. mvnForum Unspecified Cross-Site Scripting and Request Forgery // 36 views
9. Movable Type Unspecified Cross-Site Scripting Vulnerability // 36 views
10. Sunbyte e-Flower "id" SQL Injection Vulnerability // 36 views