Portable OpenSSH GSSAPI Remote Code Execution Vulnerability
BID:20241
Info
Portable OpenSSH GSSAPI Remote Code Execution Vulnerability
| Bugtraq ID: | 20241 |
| Class: | Race Condition Error |
| CVE: |
CVE-2006-5051 CVE-2008-4109 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 27 2006 12:00AM |
| Updated: | Oct 07 2008 07:48PM |
| Credit: | Mark Dowd discovered this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 lpia Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Turbolinux Turbolinux Server 10.0 x86 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Desktop 10.0 Turbolinux Turbolinux FUJI Turbolinux Turbolinux 10 F... TurboLinux Personal TurboLinux Multimedia Turbolinux Home Turbolinux Appliance Server Workgroup Edition 1.0 Turbolinux Appliance Server Hosting Edition 1.0 Turbolinux Appliance Server 1.0 Workgroup Edition Turbolinux Appliance Server 1.0 Hosting Edition Turbolinux Appliance Server 2.0 TransSoft Broker FTP Server 8.0 TransSoft Broker FTP Server 7.0 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise Desktop 10 Slackware Linux 10.2 Slackware Linux 10.1 Slackware Linux 10.0 Slackware Linux 9.1 Slackware Linux 9.0 Slackware Linux 8.1 Slackware Linux -current SGI ProPack 3.0 SP6 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Novell Linux Desktop 9 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Enterprise Server 9 S.u.S.E. Linux Enterprise Server 10 S.u.S.E. Linux Desktop 1.0 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Desktop 4.0 RedHat Desktop 3.0 Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 OpenPKG OpenPKG 2.5 OpenPKG OpenPKG 2.4 OpenPKG OpenPKG 2.3 OpenPKG OpenPKG 2.2 OpenPKG OpenPKG 2.1 OpenPKG OpenPKG 2.0 OpenPKG OpenPKG Current OpenBSD Portable OpenSSH 4.3p2 OpenBSD Portable OpenSSH 4.3p1 OpenBSD Portable OpenSSH 4.2p1 OpenBSD Portable OpenSSH 4.1p1 OpenBSD Portable OpenSSH 4.0p1 OpenBSD OpenSSH 3.8.1 p1 OpenBSD OpenSSH 3.0.2 p1 OpenBSD OpenSSH 3.0.2 OpenBSD OpenSSH 3.0.2 OpenBSD OpenSSH 3.0.1 p1 OpenBSD OpenSSH 3.0.1 OpenBSD OpenSSH 3.0 p1 OpenBSD OpenSSH 3.0 OpenBSD OpenSSH 2.9 p2 OpenBSD OpenSSH 2.9 p1 OpenBSD OpenSSH 2.9 OpenBSD OpenSSH 2.5.2 p2 OpenBSD OpenSSH 2.5.2 OpenBSD OpenSSH 2.3.1 p1 OpenBSD OpenSSH 2.3.1 OpenBSD OpenSSH 2.2 .x OpenBSD OpenSSH 2.2 .0 OpenBSD OpenSSH 2.1.1 p1 OpenBSD OpenSSH 2.1.1 OpenBSD OpenSSH 2.1 .x OpenBSD OpenSSH 2.1 OpenBSD OpenSSH 1.2.3 OpenBSD OpenSSH 1.2 OpenBSD OpenSSH 1.0 .x OpenBSD OpenSSH 4.3p1 OpenBSD OpenSSH 4.3 OpenBSD OpenSSH 4.2p1 OpenBSD OpenSSH 4.2 OpenBSD OpenSSH 4.1 OpenBSD OpenSSH 4.0 OpenBSD OpenSSH 3.9 p1 OpenBSD OpenBSD 3.9 OpenBSD OpenBSD 3.8 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 IBM AIX 5.3 L IBM AIX 5.2.2 IBM AIX 5.2 L IBM AIX 5.3 IBM AIX 5.2 Globus GSI-OpenSSH 3.8 Globus GSI-OpenSSH 3.7 Globus Globus Toolkit 4.1.1 Globus Globus Toolkit 4.1 Globus Globus Toolkit 4.0.3 Globus Globus Toolkit 4.0.2 Globus Globus Toolkit 4.0.1 Gentoo Linux FreeBSD FreeBSD 6.0 .x FreeBSD FreeBSD 6.0 -STABLE FreeBSD FreeBSD 6.0 -RELEASE FreeBSD FreeBSD 5.5 -STABLE FreeBSD FreeBSD 5.5 -RELEASE FreeBSD FreeBSD 5.4 -RELENG FreeBSD FreeBSD 5.4 -RELEASE FreeBSD FreeBSD 5.4 -PRERELEASE FreeBSD FreeBSD 5.3 -STABLE FreeBSD FreeBSD 5.3 -RELENG FreeBSD FreeBSD 5.3 -RELEASE FreeBSD FreeBSD 5.3 FreeBSD FreeBSD 5.2.1 -RELEASE FreeBSD FreeBSD 5.2 -RELENG FreeBSD FreeBSD 5.2 -RELEASE FreeBSD FreeBSD 5.2 FreeBSD FreeBSD 5.1 -RELENG FreeBSD FreeBSD 5.1 -RELEASE/Alpha FreeBSD FreeBSD 5.1 -RELEASE-p5 FreeBSD FreeBSD 5.1 -RELEASE FreeBSD FreeBSD 5.1 FreeBSD FreeBSD 5.0 .x FreeBSD FreeBSD 5.0 -RELENG FreeBSD FreeBSD 5.0 -RELEASE-p14 FreeBSD FreeBSD 5.0 alpha FreeBSD FreeBSD 5.0 FreeBSD FreeBSD 4.11 -STABLE FreeBSD FreeBSD 4.11 -RELENG FreeBSD FreeBSD 4.11 -RELEASE-p3 FreeBSD FreeBSD 4.11 -RELEASE-p20 FreeBSD FreeBSD 4.11 -RELEASE FreeBSD FreeBSD 4.10 -RELENG FreeBSD FreeBSD 4.10 -RELEASE-p8 FreeBSD FreeBSD 4.10 -RELEASE FreeBSD FreeBSD 4.10 FreeBSD FreeBSD 4.9 -RELENG FreeBSD FreeBSD 4.9 -PRERELEASE FreeBSD FreeBSD 4.9 FreeBSD FreeBSD 4.8 -RELENG FreeBSD FreeBSD 4.8 -RELEASE-p7 FreeBSD FreeBSD 4.8 -PRERELEASE FreeBSD FreeBSD 4.8 FreeBSD FreeBSD 4.7 -STABLE FreeBSD FreeBSD 4.7 -RELENG FreeBSD FreeBSD 4.7 -RELEASE-p17 FreeBSD FreeBSD 4.7 -RELEASE FreeBSD FreeBSD 4.7 FreeBSD FreeBSD 4.6.2 FreeBSD FreeBSD 4.6 -STABLE FreeBSD FreeBSD 4.6 -RELENG FreeBSD FreeBSD 4.6 -RELEASE-p20 FreeBSD FreeBSD 4.6 -RELEASE FreeBSD FreeBSD 4.6 FreeBSD FreeBSD 4.5 -STABLEpre2002-03-07 FreeBSD FreeBSD 4.5 -STABLE FreeBSD FreeBSD 4.5 -RELENG FreeBSD FreeBSD 4.5 -RELEASE-p32 FreeBSD FreeBSD 4.5 -RELEASE FreeBSD FreeBSD 4.5 FreeBSD FreeBSD 4.4 -STABLE FreeBSD FreeBSD 4.4 -RELENG FreeBSD FreeBSD 4.4 -RELENG FreeBSD FreeBSD 4.4 -RELEASE-p42 FreeBSD FreeBSD 4.4 FreeBSD FreeBSD 4.3 -STABLE FreeBSD FreeBSD 4.3 -RELENG FreeBSD FreeBSD 4.3 -RELEASE-p38 FreeBSD FreeBSD 4.3 -RELEASE FreeBSD FreeBSD 4.3 FreeBSD FreeBSD 4.2 -STABLEpre122300 FreeBSD FreeBSD 4.2 -STABLEpre050201 FreeBSD FreeBSD 4.2 -STABLE FreeBSD FreeBSD 4.2 -RELEASE FreeBSD FreeBSD 4.2 FreeBSD FreeBSD 4.1.1 -STABLE FreeBSD FreeBSD 4.1.1 -RELEASE FreeBSD FreeBSD 4.1.1 FreeBSD FreeBSD 4.1 FreeBSD FreeBSD 4.0 .x FreeBSD FreeBSD 4.0 -RELENG FreeBSD FreeBSD 4.0 alpha FreeBSD FreeBSD 4.0 FreeBSD FreeBSD 3.5.1 -STABLEpre2001-07-20 FreeBSD FreeBSD 3.5.1 -STABLE FreeBSD FreeBSD 3.5.1 -RELEASE FreeBSD FreeBSD 3.5.1 FreeBSD FreeBSD 3.5 x FreeBSD FreeBSD 3.5 -STABLEpre122300 FreeBSD FreeBSD 3.5 -STABLEpre050201 FreeBSD FreeBSD 3.5 -STABLE FreeBSD FreeBSD 3.5 FreeBSD FreeBSD 3.4 x FreeBSD FreeBSD 3.4 FreeBSD FreeBSD 3.3 x FreeBSD FreeBSD 3.3 FreeBSD FreeBSD 3.2 x FreeBSD FreeBSD 3.2 FreeBSD FreeBSD 3.1 x FreeBSD FreeBSD 3.1 FreeBSD FreeBSD 3.0 -RELENG FreeBSD FreeBSD 3.0 FreeBSD FreeBSD 2.2.8 FreeBSD FreeBSD 2.2.6 FreeBSD FreeBSD 2.2.5 FreeBSD FreeBSD 2.2.4 FreeBSD FreeBSD 2.2.3 FreeBSD FreeBSD 2.2.2 FreeBSD FreeBSD 2.2 x FreeBSD FreeBSD 2.2 FreeBSD FreeBSD 2.1.7 .1 FreeBSD FreeBSD 2.1.6 .1 FreeBSD FreeBSD 2.1.6 FreeBSD FreeBSD 2.1.5 FreeBSD FreeBSD 2.1 x FreeBSD FreeBSD 2.1 FreeBSD FreeBSD 2.0.5 FreeBSD FreeBSD 2.0 FreeBSD FreeBSD 1.1.5 .1 FreeBSD FreeBSD 6.1 -STABLE FreeBSD FreeBSD 6.1 -RELEASE FreeBSD FreeBSD 5.4-STABLE FreeBSD FreeBSD 4.10-PRERELEASE FreeBSD FreeBSD 3.x FreeBSD FreeBSD 2.x Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 2.0 Avaya Messaging Storage Server 1.0 Avaya Messaging Storage Server Avaya Message Networking Avaya Intuity LX Avaya Integrated Management 2.1 Avaya Integrated Management Avaya CVLAN Arkoon Fast360 4.0/4 Arkoon Fast360 4.0/3 Arkoon Fast360 4.0/2 Arkoon Fast360 4.0/1 Arkoon Fast360 4.0 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.3.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.3.9 |
| Not Vulnerable: |
OpenBSD Portable OpenSSH 4.4p1 OpenBSD OpenSSH 4.4 Globus GSI-OpenSSH 3.9 Globus Globus Toolkit 4.0.4 Arkoon Fast360 4.0/5 Apple Mac OS X Server 10.4.9 Apple Mac OS X 10.4.9 |
Discussion
Portable OpenSSH GSSAPI Remote Code Execution Vulnerability
Portable OpenSSH is prone to a remote code-execution vulnerability. The issue derives from a race condition in a vulnerable signal handler.
Reportedly, under specific conditions, it is theoretically possible to execute code remotely prior to authentication when GSSAPI authentication is enabled. This has not been confirmed; the chance of a successful exploit of this nature is considered minimal.
On non-Portable OpenSSH implementations, this same race condition can be exploited to cause a pre-authentication denial of service.
This issue occurs when OpenSSH and Portable OpenSSH are configured to accept GSSAPI authentication.
Portable OpenSSH is prone to a remote code-execution vulnerability. The issue derives from a race condition in a vulnerable signal handler.
Reportedly, under specific conditions, it is theoretically possible to execute code remotely prior to authentication when GSSAPI authentication is enabled. This has not been confirmed; the chance of a successful exploit of this nature is considered minimal.
On non-Portable OpenSSH implementations, this same race condition can be exploited to cause a pre-authentication denial of service.
This issue occurs when OpenSSH and Portable OpenSSH are configured to accept GSSAPI authentication.
Exploit / POC
Portable OpenSSH GSSAPI Remote Code Execution Vulnerability
To exploit these issues, attackers would likely use a modified OpenSSH client or perhaps readily available utilities that replay network packets.
To exploit these issues, attackers would likely use a modified OpenSSH client or perhaps readily available utilities that replay network packets.
Solution / Fix
Portable OpenSSH GSSAPI Remote Code Execution Vulnerability
Solution:
The vendor has released updated versions of the software that address these issues.
Please see the referenced advisories for more information and fixes.
Ubuntu Ubuntu Linux 7.10 powerpc
Turbolinux Turbolinux 10 F...
Ubuntu Ubuntu Linux 7.04 i386
Debian Linux 4.0 mips
Debian Linux 4.0 arm
Debian Linux 4.0 m68k
Apple Mac OS X Server 10.3.9
Apple Mac OS X 10.3.9
Apple Mac OS X Server 10.4
Apple Mac OS X Server 10.4.1
Apple Mac OS X 10.4.2
Apple Mac OS X Server 10.4.3
Apple Mac OS X Server 10.4.4
Apple Mac OS X Server 10.4.8
FreeBSD FreeBSD 5.0 .x
Solution:
The vendor has released updated versions of the software that address these issues.
Please see the referenced advisories for more information and fixes.
Ubuntu Ubuntu Linux 7.10 powerpc
-
Ubuntu openssh-client-udeb_4.6p1-5ubuntu0.6_powerpc.udeb
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-u deb_4.6p1-5ubuntu0.6_powerpc.udeb -
Ubuntu openssh-client_4.6p1-5ubuntu0.6_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_4 .6p1-5ubuntu0.6_powerpc.deb -
Ubuntu openssh-server-udeb_4.6p1-5ubuntu0.6_powerpc.udeb
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server-u deb_4.6p1-5ubuntu0.6_powerpc.udeb -
Ubuntu openssh-server_4.6p1-5ubuntu0.6_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_4 .6p1-5ubuntu0.6_powerpc.deb -
Ubuntu ssh-askpass-gnome_4.6p1-5ubuntu0.6_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnom e_4.6p1-5ubuntu0.6_powerpc.deb -
Ubuntu ssh-krb5_4.6p1-5ubuntu0.6_all.deb
http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/ssh-krb5_4.6 p1-5ubuntu0.6_all.deb -
Ubuntu ssh_4.6p1-5ubuntu0.6_all.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh_4.6p1-5ubunt u0.6_all.deb
Turbolinux Turbolinux 10 F...
-
Turbolinux openssh-3.8p1-9.i586.rpm
Turbolinux 10 Desktop, Turbolinux 10 F..., Turbolinux Home, Turbolinux Multimedia, Turbolinux Personal
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/openssh-3.8p1-9.i586.rpm -
Turbolinux openssh-askpass-3.8p1-9.i586.rpm
Turbolinux 10 Desktop, Turbolinux 10 F..., Turbolinux Home, Turbolinux Multimedia, Turbolinux Personal
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/openssh-askpass-3.8p1-9.i586.rpm -
Turbolinux openssh-clients-3.8p1-9.i586.rpm
Turbolinux 10 Desktop, Turbolinux 10 F..., Turbolinux Home, Turbolinux Multimedia, Turbolinux Personal
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/openssh-clients-3.8p1-9.i586.rpm -
Turbolinux openssh-server-3.8p1-9.i586.rpm
Turbolinux 10 Desktop, Turbolinux 10 F..., Turbolinux Home, Turbolinux Multimedia, Turbolinux Personal
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/openssh-server-3.8p1-9.i586.rpm
Ubuntu Ubuntu Linux 7.04 i386
-
Ubuntu openssh-client-udeb_4.3p2-8ubuntu1.5_i386.udeb
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client-u deb_4.3p2-8ubuntu1.5_i386.udeb -
Ubuntu openssh-client_4.3p2-8ubuntu1.5_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-client_4 .3p2-8ubuntu1.5_i386.deb -
Ubuntu openssh-server-udeb_4.3p2-8ubuntu1.5_i386.udeb
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server-u deb_4.3p2-8ubuntu1.5_i386.udeb -
Ubuntu openssh-server_4.3p2-8ubuntu1.5_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/openssh-server_4 .3p2-8ubuntu1.5_i386.deb -
Ubuntu ssh-askpass-gnome_4.3p2-8ubuntu1.5_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh-askpass-gnom e_4.3p2-8ubuntu1.5_i386.deb -
Ubuntu ssh-krb5_4.3p2-8ubuntu1.5_all.deb
http://security.ubuntu.com/ubuntu/pool/universe/o/openssh/ssh-krb5_4.3 p2-8ubuntu1.5_all.deb -
Ubuntu ssh_4.3p2-8ubuntu1.5_all.deb
http://security.ubuntu.com/ubuntu/pool/main/o/openssh/ssh_4.3p2-8ubunt u1.5_all.deb
Debian Linux 4.0 mips
-
Debian openssh-client-udeb_4.3p2-9etch3_mips.udeb
http://security.debian.org/pool/updates/main/o/openssh/openssh-client- udeb_4.3p2-9etch3_mips.udeb -
Debian openssh-client_4.3p2-9etch3_mips.deb
http://security.debian.org/pool/updates/main/o/openssh/openssh-client_ 4.3p2-9etch3_mips.deb -
Debian openssh-server-udeb_4.3p2-9etch3_mips.udeb
http://security.debian.org/pool/updates/main/o/openssh/openssh-server- udeb_4.3p2-9etch3_mips.udeb -
Debian openssh-server_4.3p2-9etch3_mips.deb
http://security.debian.org/pool/updates/main/o/openssh/openssh-server_ 4.3p2-9etch3_mips.deb -
Debian ssh-askpass-gnome_4.3p2-9etch3_mips.deb
http://security.debian.org/pool/updates/main/o/openssh/ssh-askpass-gno me_4.3p2-9etch3_mips.deb -
Debian ssh-krb5_4.3p2-9etch3_all.deb
http://security.debian.org/pool/updates/main/o/openssh/ssh-krb5_4.3p2- 9etch3_all.deb -
Debian ssh_4.3p2-9etch3_all.deb
http://security.debian.org/pool/updates/main/o/openssh/ssh_4.3p2-9etch 3_all.deb
Debian Linux 4.0 arm
-
Debian openssh-client-udeb_4.3p2-9etch3_arm.udeb
http://security.debian.org/pool/updates/main/o/openssh/openssh-client- udeb_4.3p2-9etch3_arm.udeb -
Debian openssh-client_4.3p2-9etch3_arm.deb
http://security.debian.org/pool/updates/main/o/openssh/openssh-client_ 4.3p2-9etch3_arm.deb -
Debian openssh-server-udeb_4.3p2-9etch3_arm.udeb
http://security.debian.org/pool/updates/main/o/openssh/openssh-server- udeb_4.3p2-9etch3_arm.udeb -
Debian openssh-server_4.3p2-9etch3_arm.deb
http://security.debian.org/pool/updates/main/o/openssh/openssh-server_ 4.3p2-9etch3_arm.deb -
Debian ssh-askpass-gnome_4.3p2-9etch3_arm.deb
http://security.debian.org/pool/updates/main/o/openssh/ssh-askpass-gno me_4.3p2-9etch3_arm.deb -
Debian ssh-krb5_4.3p2-9etch3_all.deb
http://security.debian.org/pool/updates/main/o/openssh/ssh-krb5_4.3p2- 9etch3_all.deb -
Debian ssh_4.3p2-9etch3_all.deb
http://security.debian.org/pool/updates/main/o/openssh/ssh_4.3p2-9etch 3_all.deb
Debian Linux 4.0 m68k
-
Debian ssh-krb5_4.3p2-9etch3_all.deb
http://security.debian.org/pool/updates/main/o/openssh/ssh-krb5_4.3p2- 9etch3_all.deb -
Debian ssh_4.3p2-9etch3_all.deb
http://security.debian.org/pool/updates/main/o/openssh/ssh_4.3p2-9etch 3_all.deb
Apple Mac OS X Server 10.3.9
-
Apple Mac OS X v10.4.9
http://www.apple.com/support/downloads/
Apple Mac OS X 10.3.9
-
Apple Mac OS X v10.4.9
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.4
-
Apple Mac OS X v10.4.9
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.4.1
-
Apple Mac OS X v10.4.9
http://www.apple.com/support/downloads/
Apple Mac OS X 10.4.2
-
Apple Mac OS X v10.4.9
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.4.3
-
Apple Mac OS X v10.4.9
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.4.4
-
Apple Mac OS X v10.4.9
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.4.8
-
Apple Mac OS X v10.4.9
http://www.apple.com/support/downloads/
FreeBSD FreeBSD 5.0 .x
-
FreeBSD openssh5x.patch
FreeBSD 5.x
fetch http://security.FreeBSD.org/patches/SA-06:22/openssh5x.patch
References
Portable OpenSSH GSSAPI Remote Code Execution Vulnerability
References:
References:
- Apple Homepage (Apple)
- ASA-2006-216 - openssh security update (RHSA-2006-0697) (Avaya)
- Bulletin de sécurité AK-2006-07 (Arkoon)
- OpenBSD - 015: SECURITY FIX: October 12, 2006 (OpenBSD)
- OpenBSD - 020: SECURITY FIX: October 12, 2006 (OpenBSD)
- OpenSSH 4.4 Release Notes (OpenBSD)
- RHSA-2006:0697-9 - openssh security update (Red Hat)
- [security-announce] Globus Security Advisory 2007-02: GSI-OpenSSH vulnerability (Globus)