ELBA-2024-2419

ELBA-2024-2419 - openssh bug fix and enhancement update

Type:BUG
Severity:NA
Release Date:2024-05-03

Description


[8.7p1-38.0.1]
- Update upstream references [Orabug: 36564626]

[8.7p1-38]
- Fix Terrapin attack
Resolves: CVE-2023-48795

[8.7p1-37]
- Fix Terrapin attack
Resolves: CVE-2023-48795

[8.7p1-36]
- Fix Terrapin attack
Resolves: CVE-2023-48795
- Relax OpenSSH build-time checks for OpenSSL version
Related: RHEL-4734
- Forbid shell metasymbols in username/hostname
Resolves: CVE-2023-51385

[8.7p1-35]
- Relax OpenSSH checks for OpenSSL version
Resolves: RHEL-4734
- Limit artificial delays in sshd while login using AD user
Resolves: RHEL-2469
- Move users/groups creation logic to sysusers.d fragments
Resolves: RHEL-5222




Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) openssh-8.7p1-38.0.1.el9.src.rpme5ffab426f595f1be5e9c33ddabe6265-ol9_aarch64_appstream
openssh-8.7p1-38.0.1.el9.src.rpme5ffab426f595f1be5e9c33ddabe6265-ol9_aarch64_baseos_latest
openssh-8.7p1-38.0.1.el9.src.rpme5ffab426f595f1be5e9c33ddabe6265-ol9_aarch64_u4_baseos_base
openssh-8.7p1-38.0.1.el9.aarch64.rpmac7bc902a4415dfcff44c78100a3d9fa-ol9_aarch64_baseos_latest
openssh-8.7p1-38.0.1.el9.aarch64.rpmac7bc902a4415dfcff44c78100a3d9fa-ol9_aarch64_u4_baseos_base
openssh-askpass-8.7p1-38.0.1.el9.aarch64.rpm1d6115b8cad140b0aa2bab6921278966-ol9_aarch64_appstream
openssh-clients-8.7p1-38.0.1.el9.aarch64.rpm4d69d300d7c351edf370c8ab1109c5db-ol9_aarch64_baseos_latest
openssh-clients-8.7p1-38.0.1.el9.aarch64.rpm4d69d300d7c351edf370c8ab1109c5db-ol9_aarch64_u4_baseos_base
openssh-keycat-8.7p1-38.0.1.el9.aarch64.rpmc541b5bba1ba7fcfc81d2ed1e1b025a8-ol9_aarch64_baseos_latest
openssh-keycat-8.7p1-38.0.1.el9.aarch64.rpmc541b5bba1ba7fcfc81d2ed1e1b025a8-ol9_aarch64_u4_baseos_base
openssh-server-8.7p1-38.0.1.el9.aarch64.rpmd9c5cce0fc15baf453ce3a8b22fb6bcb-ol9_aarch64_baseos_latest
openssh-server-8.7p1-38.0.1.el9.aarch64.rpmd9c5cce0fc15baf453ce3a8b22fb6bcb-ol9_aarch64_u4_baseos_base
pam_ssh_agent_auth-0.10.4-5.38.0.1.el9.aarch64.rpmcac3fbee99e4d185f2508a344b4d9922-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) openssh-8.7p1-38.0.1.el9.src.rpme5ffab426f595f1be5e9c33ddabe6265-ol9_x86_64_appstream
openssh-8.7p1-38.0.1.el9.src.rpme5ffab426f595f1be5e9c33ddabe6265-ol9_x86_64_baseos_latest
openssh-8.7p1-38.0.1.el9.src.rpme5ffab426f595f1be5e9c33ddabe6265-ol9_x86_64_u4_baseos_base
openssh-8.7p1-38.0.1.el9.x86_64.rpmea324cc47aa23c41f4559702aa633f9d-ol9_x86_64_baseos_latest
openssh-8.7p1-38.0.1.el9.x86_64.rpmea324cc47aa23c41f4559702aa633f9d-ol9_x86_64_u4_baseos_base
openssh-askpass-8.7p1-38.0.1.el9.x86_64.rpmcee05c282a636ef48da47a76dae54962-ol9_x86_64_appstream
openssh-clients-8.7p1-38.0.1.el9.x86_64.rpm873bf3ff37d88b29fee22de717a6db7c-ol9_x86_64_baseos_latest
openssh-clients-8.7p1-38.0.1.el9.x86_64.rpm873bf3ff37d88b29fee22de717a6db7c-ol9_x86_64_u4_baseos_base
openssh-keycat-8.7p1-38.0.1.el9.x86_64.rpm747ff85636ab80274a34ede32458f25b-ol9_x86_64_baseos_latest
openssh-keycat-8.7p1-38.0.1.el9.x86_64.rpm747ff85636ab80274a34ede32458f25b-ol9_x86_64_u4_baseos_base
openssh-server-8.7p1-38.0.1.el9.x86_64.rpm4199ae26bc28b8441f39734e2fbbc0d5-ol9_x86_64_baseos_latest
openssh-server-8.7p1-38.0.1.el9.x86_64.rpm4199ae26bc28b8441f39734e2fbbc0d5-ol9_x86_64_u4_baseos_base
pam_ssh_agent_auth-0.10.4-5.38.0.1.el9.x86_64.rpm235d988fd3cdb071119f19b00ac78d34-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete