Gentoo: openssh Information disclosure vulnerability
Summary
- - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200305-01 - - ---------------------------------------------------------------------
- - ---------------------------------------------------------------------
Mediaservice.net has discovered a bug in OpenSSH that allows attackersto identify valid users on vulnerable systems.
Read the full advisory at
SOLUTION
It is recommended that all Gentoo Linux users who are running net-misc/openssh upgrade to openssh-3.6.1_p2 as follows:
emerge sync emerge openssh emerge clean
- - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at - - ---------------------------------------------------------------------
Resolution
References
Availability
Concerns
Background