[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2009:1470-01 -- Redhat openssh

ID: oval:org.secpod.oval:def:500680Date: (C)2012-01-31   (M)2021-09-12
Class: PATCHFamily: unix




OpenSSH is OpenBSD"s SSH protocol implementation. These packages include the core files necessary for both the OpenSSH client and server. A Red Hat specific patch used in the openssh packages as shipped in Red Hat Enterprise Linux 5.4 loosened certain ownership requirements for directories used as arguments for the ChrootDirectory configuration options. A malicious user that also has or previously had non-chroot shell access to a system could possibly use this flaw to escalate their privileges and run commands as any system user. All OpenSSH users are advised to upgrade to these updated packages, which contain a backported patch to resolve this issue. After installing this update, the OpenSSH server daemon will be restarted automatically.

Platform:
Red Hat Enterprise Linux 5
Product:
openssh
Reference:
RHSA-2009:1470-01
CVE-2009-2904
CVE    1
CVE-2009-2904
CPE    2
cpe:/o:redhat:enterprise_linux:5
cpe:/a:openbsd:openssh

© SecPod Technologies