Publisher Name: OpenPKG GmbH Publisher Home: http://openpkg.com/ Advisory Id (public): OpenPKG-SA-2003.040 Advisory Type: OpenPKG Security Advisory (SA) Advisory Directory: http://openpkg.com/go/OpenPKG-SA Advisory Document: http://openpkg.com/go/OpenPKG-SA-2003.040 Advisory Published: 2010-09-03 22:25 UTC Issue Id (internal): OpenPKG-SI-20030917.01 Issue First Created: 2003-09-17 Issue Last Modified: 2006-11-28 Issue Revision: 06
Subject Name: OpenSSH Subject Summary: Secure Shell (SSH) Subject Home: http://www.openssh.com/ Subject Versions: * <= 3.7p1 Vulnerability Id: CVE-2003-0693 Vulnerability Scope: global (not OpenPKG specific) Attack Feasibility: run-time Attack Vector: remote network Attack Impact: arbitrary code execution Description: According to an OpenSSH [1] Security Advisory [0], 2nd revision, all versions of OpenSSH's sshd(8) prior to version 3.7.1 contain buffer management errors. The discovery of additional similar errors by Solar Designer show that version 3.7.1 is affected, too. Those errors may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be cleared and corrupting the heap on fatal cleanups. CVE-2003-0693 initially explained in the 1st revision of the OpenSSH Security Advisory [0]. In the current 2nd revision, similar problems were described and fixed, too. Additionally, Solaris Designer found 4 more problematic instances of similar memory management errors. The corrected OpenPKG packages (see versions above) contain the collected bug fixes for all of those errors. References: [0] http://www.openssh.com/txt/buffer.adv [1] http://www.openssh.com/ [2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0693 [3] http://www.openpkg.org/tutorial.html#regular-source [4] http://www.openpkg.org/tutorial.html#regular-binary [5] ftp://ftp.openpkg.org/release/1.3/UPD/openssh-3.6.1p2-1.3.2.src.rpm [6] ftp://ftp.openpkg.org/release/1.2/UPD/openssh-3.5p1-1.2.4.src.rpm [8] ftp://ftp.openpkg.org/release/1.3/UPD/ [7] ftp://ftp.openpkg.org/release/1.2/UPD/ [9] http://www.openpkg.org/security.html#signature
Primary Package Name: openssh Primary Package Home: http://openpkg.org/go/package/openssh Affected Distribution: Affected Branch: Affected Package: OpenPKG Community 1.2-SOLID openssh-3.5p1-1.2.3 OpenPKG Community 1.3-SOLID openssh-3.6.1p2-1.3.1 OpenPKG Community CURRENT openssh-3.7p1-20030916 Corrected Distribution: Corrected Branch: Corrected Package: OpenPKG Community 1.2-SOLID openssh-3.5p1-1.2.4 OpenPKG Community 1.3-SOLID openssh-3.6.1p2-1.3.2 OpenPKG Community CURRENT openssh-3.7.1p1-20030917