|
Family: Ubuntu Local Security Checks --> Category: infos
USN209-1 : openssh vulnerability Vulnerability Scan
Vulnerability Scan Summary openssh vulnerability
Detailed Explanation for this Vulnerability Test
Synopsis :
These remote packages are missing security patches :
- openssh-client
- openssh-server
- ssh
- ssh-askpass-gnome
Description :
An information disclosure vulnerability has been found in the SSH
server. When the GSSAPIAuthentication option was enabled, the SSH
server could send GSSAPI credentials even to users who attempted to
log in with a method other than GSSAPI. This could inadvertently
expose these credentials to an untrusted user.
Please note that this does not affect the default configuration of the
SSH server.
Solution :
Upgrade to :
- openssh-client-3.9p1-1ubuntu2.1 (Ubuntu 5.04)
- openssh-server-3.9p1-1ubuntu2.1 (Ubuntu 5.04)
- ssh-3.9p1-1ubuntu2.1 (Ubuntu 5.04)
- ssh-askpass-gnome-3.9p1-1ubuntu2.1 (Ubuntu 5.04)
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|