openssh 1:4.2p1-7ubuntu3.1 source package in Ubuntu

Changelog

openssh (1:4.2p1-7ubuntu3.1) dapper-security; urgency=low

  * SECURITY UPDATE: Remote DoS.
  * CVE-2006-4924: Fix a pre-authentication denial of service found by
    Tavis Ormandy, that would cause sshd(8) to spin until the login grace
    time expired.
    Upstream fixes:
    http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/deattack.c.diff?r1=1.29&r2=1.30&sortby=date&f=h
    http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/packet.c.diff?r1=1.143&r2=1.144&sortby=date&f=h
    http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/deattack.h.diff?r1=1.9&r2=1.10&sortby=date&f=h
  * Fix an unsafe signal hander reported by Mark Dowd. The
    signal handler was vulnerable to a race condition that could be
    exploited to perform a pre-authentication denial of service. [CVE-2006-5051]
    On portable OpenSSH, this vulnerability could theoretically lead to
    pre-authentication remote code execution if GSSAPI authentication is
    enabled, but the likelihood of successful exploitation appears remote.
    [CVE-2006-5052]
  * Above patches taken from Debian's 4.3p2-4 version, thanks to Colin Watson
    for backporting them from 4.4p1.
  * packet.c: Fix a NULL dereference crash so that an appropriate error
    message is printed on a protocol error. This is not actually a
    vulnerability, but has been assigned CVE-2006-4925, so let's fix it for
    completeness' sake.
    Taken from upstream CVS:
    http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/packet.c.diff?sortby=date&r2=1.145&r1=1.144&f=h

 -- Martin Pitt <email address hidden>   Mon,  2 Oct 2006 09:38:59 +0000

Upload details

Uploaded by:
Martin Pitt
Uploaded to:
Dapper
Original maintainer:
Matthew Vernon
Architectures:
any
Section:
net
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
openssh_4.2p1.orig.tar.gz 906.7 KiB 071582e57d13991547b3b5596c2f33f047468b7e272f6e36336d2e1f2f34e0e8
openssh_4.2p1-7ubuntu3.1.diff.gz 167.3 KiB 7b9a269d2e04e12a857c16de137d77a3c22ca28bbc2aba10f7ffe1bfb53309d7
openssh_4.2p1-7ubuntu3.1.dsc 1005 bytes cb4463884a4421a4a48575540308525e10021cadd727d4a3e7f4c9f710bfa89f

View changes file

Binary packages built by this source

openssh-client: No summary available for openssh-client in ubuntu dapper.

No description available for openssh-client in ubuntu dapper.

openssh-client-udeb: No summary available for openssh-client-udeb in ubuntu dapper.

No description available for openssh-client-udeb in ubuntu dapper.

openssh-server: No summary available for openssh-server in ubuntu dapper.

No description available for openssh-server in ubuntu dapper.

openssh-server-udeb: No summary available for openssh-server-udeb in ubuntu dapper.

No description available for openssh-server-udeb in ubuntu dapper.

ssh: No summary available for ssh in ubuntu dapper.

No description available for ssh in ubuntu dapper.

ssh-askpass-gnome: No summary available for ssh-askpass-gnome in ubuntu dapper.

No description available for ssh-askpass-gnome in ubuntu dapper.