The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

REMOTE EXPLOIT IN SSHD

Discussion in 'General Discussion' started by zex, Jun 27, 2002.

  1. zex

    zex Well-Known Member

    Joined:
    Aug 12, 2001
    Messages:
    98
    Likes Received:
    0
    Trophy Points:
    6
    cPanel Access Level:
    Root Administrator
    According to latest news about bug in ssh this seems to be more dangerous than recent apache bug.

    It's much easier exploitable than recent apache hole.
    At least one major security vulnerability exists in many deployed OpenSSH versions (2.9.9 to 3.3). Systems running with UsePrivilegeSeparation yes or ChallengeResponseAuthentication no are not affected.

    Here is ISS advisory http://www.openssh.com/txt/iss.adv
    and here is openssh advisory http://www.openssh.com/txt/preauth.adv
    It's strongly recomended upgrading openssh to 3.4 version.
     
  2. snowgod

    snowgod Well-Known Member

    Joined:
    Sep 23, 2001
    Messages:
    73
    Likes Received:
    0
    Trophy Points:
    6
    we already have a thread on this http://forums.cpanel.net/read.php?TID=3532

    just trying to keep things centralized :)
     
Loading...

Share This Page