-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________ Caldera International, Inc. Security Advisory Subject: Linux: OpenSSH channel code vulnerability Advisory number: CSSA-2002-012.0 Issue date: 2002, March 28 Cross reference: ______________________________________________________________________________ 1. Problem Description A bug exists in the channel code of OpenSSH versions 2.0 though 3.0.2. Existing users can use this bug to gain root privileges. The ability to exploit this vulnerability without an existing user account has not yet been proven, but it is considered possible. A malicious ssh server could also use this bug to exploit a connecting vulnerable client. 2. Vulnerable Supported Versions System Package ---------------------------------------------------------------------- OpenLinux 3.1.1 Server prior to openssh-2.9.9p2-3.i386.rpm prior to openssh-2.9.9p2-3.src.rpm prior to openssh-askpass-2.9.9p2-3.i386.rpm prior to openssh-server-2.9.9p2-3.i386.rpm OpenLinux 3.1.1 Workstation prior to openssh-2.9.9p2-3.i386.rpm prior to openssh-2.9.9p2-3.src.rpm prior to openssh-askpass-2.9.9p2-3.i386.rpm prior to openssh-server-2.9.9p2-3.i386.rpm OpenLinux 3.1 Server prior to openssh-2.9p2-5.i386.rpm prior to openssh-2.9p2-5.src.rpm prior to openssh-askpass-2.9p2-5.i386.rpm prior to openssh-server-2.9p2-5.i386.rpm OpenLinux 3.1 Workstation prior to openssh-askpass-2.9p2-5.i386.rpm prior to openssh-server-2.9p2-5.i386.rpm prior to openssh-2.9p2-5.i386.rpm prior to openssh-2.9p2-5.src.rpm 3. Solution The proper solution is to install the latest packages. 4. OpenLinux 3.1.1 Server 4.1 Package Location ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS 4.2 Packages 523a21268ec04feb84feaf8a8b41bb3c openssh-2.9.9p2-3.i386.rpm c318d432f54351a26f7054907656cca3 openssh-askpass-2.9.9p2-3.i386.rpm f00823740075a9ae04f2e116d099c625 openssh-server-2.9.9p2-3.i386.rpm 4.3 Installation rpm -Fvh openssh-2.9.9p2-3.i386.rpm rpm -Fvh openssh-askpass-2.9.9p2-3.i386.rpm rpm -Fvh openssh-server-2.9.9p2-3.i386.rpm 4.4 Source Package Location ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/SRPMS 4.5 Source Packages 7217833a00aca91ad41472b2fe27725e openssh-2.9.9p2-3.src.rpm 5. OpenLinux 3.1.1 Workstation 5.1 Package Location ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS 5.2 Packages 523a21268ec04feb84feaf8a8b41bb3c openssh-2.9.9p2-3.i386.rpm c318d432f54351a26f7054907656cca3 openssh-askpass-2.9.9p2-3.i386.rpm f00823740075a9ae04f2e116d099c625 openssh-server-2.9.9p2-3.i386.rpm 5.3 Installation rpm -Fvh openssh-2.9.9p2-3.i386.rpm rpm -Fvh openssh-askpass-2.9.9p2-3.i386.rpm rpm -Fvh openssh-server-2.9.9p2-3.i386.rpm 5.4 Source Package Location ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/SRPMS 5.5 Source Packages 7217833a00aca91ad41472b2fe27725e openssh-2.9.9p2-3.src.rpm 6. OpenLinux 3.1 Server 6.1 Package Location ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Server/current/RPMS 6.2 Packages f628846edca7e40cebf0174d4a02abb9 openssh-2.9p2-5.i386.rpm c9c56667fdfd28c4b92474369d802ca9 openssh-askpass-2.9p2-5.i386.rpm 0aee5aedf111ffb8a6ff27a120b0eaf3 openssh-server-2.9p2-5.i386.rpm 6.3 Installation rpm -Fvh openssh-2.9p2-5.i386.rpm rpm -Fvh openssh-askpass-2.9p2-5.i386.rpm rpm -Fvh openssh-server-2.9p2-5.i386.rpm 6.4 Source Package Location ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Server/current/SRPMS 6.5 Source Packages b7a1c7a46aa2f6a43b0cabb11df8ec66 openssh-2.9p2-5.src.rpm 7. OpenLinux 3.1 Workstation 7.1 Package Location ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Workstation/current/RPMS 7.2 Packages c9c56667fdfd28c4b92474369d802ca9 openssh-askpass-2.9p2-5.i386.rpm 0aee5aedf111ffb8a6ff27a120b0eaf3 openssh-server-2.9p2-5.i386.rpm f628846edca7e40cebf0174d4a02abb9 openssh-2.9p2-5.i386.rpm 7.3 Installation rpm -Fvh openssh-askpass-2.9p2-5.i386.rpm rpm -Fvh openssh-server-2.9p2-5.i386.rpm rpm -Fvh openssh-2.9p2-5.i386.rpm 7.4 Source Package Location ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1/Workstation/current/SRPMS 7.5 Source Packages b7a1c7a46aa2f6a43b0cabb11df8ec66 openssh-2.9p2-5.src.rpm 8. References Specific references for this advisory: none Caldera OpenLinux security resources: http://www.caldera.com/support/security/index.html Caldera UNIX security resources: http://stage.caldera.com/support/security/ This security fix closes Caldera incidents sr861333, fz520313, erg711982. 9. Disclaimer Caldera International, Inc. is not responsible for the misuse of any of the information we provide on this website and/or through our security advisories. Our advisories are a service to our customers intended to promote secure installation and use of Caldera products. 10. Acknowledgements Joost Pol discovered and researched this vulnerability. ______________________________________________________________________________ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see http://www.gnupg.org iEYEARECAAYFAjyt3xoACgkQbluZssSXDTGGgQCfVdYIito3dw91tW+mfV8ndjg2 sk0AoPsVdQNZ+XSokDXDoMWVXF4Z1Efz =1ssp -----END PGP SIGNATURE-----