Gentoo: openssh Buffer management error
Summary
- - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200309-11 - - ---------------------------------------------------------------------
- - ---------------------------------------------------------------------
quote from advisory:
"All versions of OpenSSH's sshd prior to 3.7 contain a buffer management error. It is uncertain whether this error is potentially exploitable, however, we prefer to see bugs fixed proactively."
read the full advisory at: openssh
SOLUTION
It is recommended that all Gentoo Linux users who are running net-misc/openssh upgrade to openssh-3.7_p1 as follows:
emerge sync emerge openssh emerge clean
- - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at vapier@gentoo.org - - ---------------------------------------------------------------------
Resolution
References
Availability
Concerns
Background