Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 1638-1] New openssh packages fix denial of service (1/2

    From Florian Weimer@1:229/2 to All on Tue Sep 16 22:50:14 2008
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-1638-1 [email protected] http://www.debian.org/security/ Florian Weimer September 16, 2008 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : openssh
    Vulnerability : remote
    Problem type : unsafe signal handler
    Debian-specific: no
    CVE Id(s) : CVE-2008-4109
    Debian Bug : 498678

    It has been discovered that the signal handler implementing the login
    timeout in Debian's version of the OpenSSH server uses functions which
    are not async-signal-safe, leading to a denial of service
    vulnerability (CVE-2008-4109).

    The problem was originally corrected in OpenSSH 4.4p1 (CVE-2006-5051),
    but the patch backported to the version released with etch was
    incorrect.

    Systems affected by this issue suffer from lots of zombie sshd
    processes. Processes stuck with a "[net]" process title have also been observed. Over time, a sufficient number of processes may accumulate
    such that further login attempts are impossible. Presence of these
    processes does not indicate active exploitation of this vulnerability.
    It is possible to trigger this denial of service condition by accident.

    For the stable distribution (etch), this problem has been fixed in
    version 4.3p2-9etch3.

    For the unstable distribution (sid) and the testing distribution
    (lenny), this problem has been fixed in version 4.6p1-1.

    We recommend that you upgrade your openssh packages.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 4.0 alias etch
    - -------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/o/openssh/openssh_4.3p2-9etch3.diff.gz
    Size/MD5 checksum: 275859 d36cb34826bb92eca24a9397369baee6
    http://security.debian.org/pool/updates/main/o/openssh/openssh_4.3p2.orig.tar.gz
    Size/MD5 checksum: 920186 239fc801443acaffd4c1f111948ee69c
    http://security.debian.org/pool/updates/main/o/openssh/openssh_4.3p2-9etch3.dsc
    Size/MD5 checksum: 1310 1888a56e6050c8b8c2caf95e9da1db84

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/o/openssh/ssh-krb5_4.3p2-9etch3_all.deb
    Size/MD5 checksum: 91378 2748b67458de398e05e7c05227a0c612
    http://security.debian.org/pool/updates/main/o/openssh/ssh_4.3p2-9etch3_all.deb
    Size/MD5 checksum: 1052 f47a80d017cd3184bc981a38ced31ee8

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/o/openssh/openssh-client_4.3p2-9etch3_alpha.deb
    Size/MD5 checksum: 782932 e7f3b896603dc1aebadb370d79ab90f5
    http://security.debian.org/pool/updates/main/o/openssh/ssh-askpass-gnome_4.3p2-9etch3_alpha.deb
    Size/MD5 checksum: 100580 8ed4b61e252f3080073134abae2a36cd
    http://security.debian.org/pool/updates/main/o/openssh/openssh-server-udeb_4.3p2-9etch3_alpha.udeb
    Size/MD5 checksum: 213712 9eb6b65f9292db607a4b2d6bf498c54f
    http://security.debian.org/pool/updates/main/o/openssh/openssh-server_4.3p2-9etch3_alpha.deb
    Size/MD5 checksum: 266512 81805fcb11c56d7252ecdf4a1e74d713
    http://security.debian.org/pool/updates/main/o/openssh/openssh-client-udeb_4.3p2-9etch3_alpha.udeb
    Size/MD5 checksum: 198516 d294a1db5f4257c4c58154bb160232f1

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/o/openssh/openssh-client_4.3p2-9etch3_amd64.deb
    Size/MD5 checksum: 710490 816deaa292a89d07a1d8b6ad196eb72d
    http://security.debian.org/pool/updates/main/o/openssh/ssh-askpass-gnome_4.3p2-9etch3_amd64.deb
    Size/MD5 checksum: 99976 05a863e6cd0aaced1cf8c774d7573274
    http://security.debian.org/pool/updates/main/o/openssh/openssh-server-udeb_4.3p2-9etch3_amd64.udeb
    Size/MD5 checksum: 183846 a9c89a870bb58463606ec8b736643144
    http://security.debian.org/pool/updates/main/o/openssh/openssh-server_4.3p2-9etch3_amd64.deb
    Size/MD5 checksum: 244368 9d0b3126c34e338b4f5216284518aea8
    http://security.debian.org/pool/updates/main/o/openssh/openssh-client-udeb_4.3p2-9etch3_amd64.udeb
    Size/MD5 checksum: 171380 2cf03617de7bd22ff03b85f8ca2b25f0

    arm architecture (ARM)

    http://security.debian.org/pool/updates/main/o/openssh/openssh-client_4.3p2-9etch3_arm.deb
    Size/MD5 checksum: 650726 a50736277f77d29a8cd59be5de31efe8
    http://security.debian.org/pool/updates/main/o/openssh/ssh-askpass-gnome_4.3p2-9etch3_arm.deb
    Size/MD5 checksum: 99754 bee5a81d4168699a324ff572d6e436d6
    http://security.debian.org/pool/updates/main/o/openssh/openssh-client-udeb_4.3p2-9etch3_arm.udeb
    Size/MD5 checksum: 164866 067f69be0283f3bb3cf697f4312d2bbb
    http://security.debian.org/pool/updates/main/o/openssh/openssh-server_4.3p2-9etch3_arm.deb
    Size/MD5 checksum: 218966 2a8dfbfc4e5abe2d333f20e123ad38ad
    http://security.debian.org/pool/updates/main/o/openssh/openssh-server-udeb_4.3p2-9etch3_arm.udeb
    Size/MD5 checksum: 171672 a0ce63abaee1e7cfbaf64e62dc8164b5

    hppa architecture (HP PA RISC)

    http://security.debian.org/pool/updates/main/o/openssh/openssh-client_4.3p2-9etch3_hppa.deb
    Size/MD5 checksum: 732946 3177a89f68634880a3da10e054abe538
    http://security.debian.org/pool/updates/main/o/openssh/openssh-client-udeb_4.3p2-9etch3_hppa.udeb
    Size/MD5 checksum: 189606 92ce0ac13874e3ec7ef20e7d97221850
    http://security.debian.org/pool/updates/main/o/openssh/openssh-server_4.3p2-9etch3_hppa.deb
    Size/MD5 checksum: 249864 191165420d41b4ea84f7ae820a61dee1
    http://security.debian.org/pool/updates/main/o/openssh/openssh-server-udeb_4.3p2-9etch3_hppa.udeb
    Size/MD5 checksum: 198138 af0b7c29c951135595170b63251dd484
    http://security.debian.org/pool/updates/main/o/openssh/ssh-askpass-gnome_4.3p2-9etch3_hppa.deb
    Size/MD5 checksum: 100532 55db615aae32e2adf40dbe79b5fc7cf1

    i386 architecture (Intel ia32)

    http://security.debian.org/pool/updates/main/o/openssh/ssh-askpass-gnome_4.3p2-9etch3_i386.deb

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Krenn
      Tue Jun 9 11:18:15 2026
      from Sydney, Nsw via Telnet
    • Bob Worm
      Tue Jun 9 10:31:07 2026
      from Wales, Uk via Telnet
    • Centurion
      Mon Jun 8 23:30:43 2026
      from Berea, Ohio via Telnet
    • Centurion
      Mon Jun 8 21:33:11 2026
      from Berea, Ohio via Telnet
    • Bob Worm
      Mon Jun 8 20:15:00 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 16:33:22 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 14:11:46 2026
      from Wales, Uk via Telnet
    • Krenn
      Mon Jun 8 11:22:02 2026
      from Sydney, Nsw via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (3 / 13)
    Uptime: 43:05:43
    Calls: 12,111
    Calls today: 2
    Files: 15,008
    Messages: 6,518,438

© >>> Magnum BBS <<<, 2026