Secunia Logo
 
OpenLinux update for OpenSSH
Secunia Advisory: SA9922
Release Date: 2003-10-03
Popularity: 5,419 views

Critical:
Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch

OS:OpenLinux Server 3.x
OpenLinux Workstation 3.x

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2003-0693
CVE-2003-0695
CVE-2003-0682
CVE-2003-0786


Description:
SCO has issued updated packages for OpenSSH. These fixes multiple vulnerabilities, which potentially can be exploited by malicious people to compromise a vulnerable system.

For more information:
SA9743
SA9825

Solution:
Updated packages:

OpenLinux 3.1.1 Server

ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2003-027.0/RPMS

b221123334fd2dbe93d049038175f91b openssh-3.7.1p2-1.i386.rpm
3290dd2b9cacfc1c7188b9a744645123 openssh-askpass-3.7.1p2-1.i386.rpm
e5f5d9bbbfeb4e97629dae7b2446418f openssh-server-3.7.1p2-1.i386.rpm

ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2003-027.0/SRPMS

19fba72b17344b49390210f7988c3d0f openssh-3.7.1p2-1.src.rpm

OpenLinux 3.1.1 Workstation

ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2003-027.0/RPMS

ecae4ebd7d44036200fca7f4e7a00c85 openssh-3.7.1p2-1.i386.rpm
086fd39a605fb8e5332ddeb9ad57d271 openssh-askpass-3.7.1p2-1.i386.rpm
d1bf2e78daf806738bdedfcef9587830 openssh-server-3.7.1p2-1.i386.rpm

ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2003-027.0/SRPMS

3cb08e4470041e84b893618a2df75bf1 openssh-3.7.1p2-1.src.rpm

Original Advisory:
ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-027.0.txt

Other References:
SA9743:
http://secunia.com/advisories/9743/

SA9825:
http://secunia.com/advisories/9825/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 99 views
2. VMware ESX / ESXi Virtual Hardware Memory Corruption Vulnerability // 55 views
3. SquirrelMail Malformed HTML Mail Message Script Insertion // 55 views
4. VMware ESX Server update for bzip2 // 54 views
5. Subdreamer Light Global Variables SQL Injection Vulnerability // 46 views
6. Adobe Flash Player Multiple Security Issues and Vulnerabilities // 41 views
7. HP-UX Unspecified Local Denial of Service Vulnerability // 41 views
8. phpBB Avatar Functions Information Disclosure and Deletion // 40 views
9. mvnForum Unspecified Cross-Site Scripting and Request Forgery // 37 views
10. Kolab Server ClamAV Multiple Vulnerabilities // 34 views