drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mangelnde Rechteprüfung in gsi-openssh
Name: |
Mangelnde Rechteprüfung in gsi-openssh |
|
ID: |
FEDORA-2019-710afd062a |
|
Distribution: |
Fedora |
|
Plattformen: |
Fedora 28 |
|
Datum: |
Mo, 18. Februar 2019, 07:15 |
|
Referenzen: |
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7639 |
|
Applikationen: |
GSI-OpenSSH |
|
Originalnachricht |
------------------------------------------------------------------------------- - Fedora Update Notification FEDORA-2019-710afd062a 2019-02-18 01:25:49.106963 ------------------------------------------------------------------------------- -
Name : gsi-openssh Product : Fedora 28 Version : 7.8p1 Release : 3.fc28 URL : http://www.openssh.com/portable.html Summary : An implementation of the SSH protocol with GSI authentication Description : SSH (Secure SHell) is a program for logging into and executing commands on a remote machine. SSH is intended to replace rlogin and rsh, and to provide secure encrypted communications between two untrusted hosts over an insecure network. X11 connections and arbitrary TCP/IP ports can also be forwarded over the secure channel.
OpenSSH is OpenBSD's version of the last free version of SSH, bringing it up to date in terms of security and features.
This version of OpenSSH has been modified to support GSI authentication.
This package includes the core files necessary for both the gsissh client and server. To make this package useful, you should also install gsi-openssh-clients, gsi-openssh-server, or both.
------------------------------------------------------------------------------- - Update Information:
CVE-2019-7639 ------------------------------------------------------------------------------- - ChangeLog:
* Fri Feb 8 2019 Mattias Ellert <mattias.ellert@physics.uu.se> - 7.8p1-3 - CVE-2019-7639 * Tue Jan 15 2019 Mattias Ellert <mattias.ellert@physics.uu.se> - 7.8p1-2 - Based on openssh-7.8p1-4.fc28 * Tue Oct 23 2018 Mattias Ellert <mattias.ellert@physics.uu.se> - 7.8p1-1 - Based on openssh-7.8p1-3.fc28 * Thu Aug 16 2018 Mattias Ellert <mattias.ellert@physics.uu.se> - 7.7p1-5 - Based on openssh-7.7p1-6.fc28 * Fri Jul 13 2018 Fedora Release Engineering <releng@fedoraproject.org> - 7.7p1-4.1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Thu Jul 5 2018 Mattias Ellert <mattias.ellert@physics.uu.se> - 7.7p1-4 - Based on openssh-7.7p1-5.fc28 * Tue Apr 17 2018 Mattias Ellert <mattias.ellert@physics.uu.se> - 7.7p1-3 - Based on openssh-7.7p1-3.fc28 * Thu Apr 12 2018 Mattias Ellert <mattias.ellert@physics.uu.se> - 7.7p1-2 - Based on openssh-7.7p1-2.fc28 * Tue Apr 10 2018 Mattias Ellert <mattias.ellert@physics.uu.se> - 7.7p1-1 - Based on openssh-7.7p1-1.fc28 ------------------------------------------------------------------------------- - References:
[ 1 ] Bug #1673802 - CVE-2019-7639 gsi-openssh: enabling PermitPAMUserChange allows to login with the correct username and wrong password [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1673802 ------------------------------------------------------------------------------- -
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-710afd062a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys ------------------------------------------------------------------------------- - _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org
|
|
|
|