ELSA-2013-1591

ELSA-2013-1591 - openssh security, bug fix, and enhancement update

Type:SECURITY
Impact:LOW
Release Date:2013-11-26

Description


[5.3p1-94]
- use dracut-fips package to determine if a FIPS module is installed (#1001565)

[5.3p1-93]
- use dist tag in suffixes for hmac checksum files (#1001565)

[5.3p1-92]
- use hmac_suffix for ssh{,d} hmac checksums (#1001565)

[5.3p1-91]
- fix NSS keys support (#1004763)

[5.3p1-90]
- change default value of MaxStartups - CVE-2010-5107 - #908707
- add -fips subpackages that contains the FIPS module files (#1001565)

[5.3p1-89]
- don't use SSH_FP_MD5 for fingerprints in FIPS mode (#998835)

[5.3p1-88]
- do ssh_gssapi_krb5_storecreds() twice - before and after pam sesssion (#974096)

[5.3p1-87]
- bump the minimum value of SSH_USE_STRONG_RNG to 14 according to SP800-131A (#993577)
- fixed an issue with broken 'ssh -I pkcs11' (#908038)
- abort non-subsystem sessions to forced internal sftp-server (#993509)
- reverted 'store krb5 credentials after a pam session is created (#974096)'

[5.3p1-86]
- Add support for certificate key types for users and hosts (#906872)
- Apply RFC3454 stringprep to banners when possible (#955792)

[5.3p1-85]
- fix chroot logging issue (#872169)
- change the bad key permissions error message (#880575)
- fix a race condition in ssh-agent (#896561)
- backport support for PKCS11 from openssh-5.4p1 (#908038)
- add a KexAlgorithms knob to the client and server configuration (#951704)
- fix parsing logic of ldap.conf file (#954094)
- Add HMAC-SHA2 algorithm support (#969565)
- store krb5 credentials after a pam session is created (#974096)


Related CVEs


CVE-2010-5107

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 6 (i386) openssh-5.3p1-94.el6.src.rpme631856adeef7872d50691131a965667c7feb4f238cc0c7c20aba2ac35e43efeELSA-2023-4428ol6_i386_latest_archive
openssh-5.3p1-94.el6.src.rpme631856adeef7872d50691131a965667c7feb4f238cc0c7c20aba2ac35e43efeELSA-2023-4428ol6_u5_i386_base
openssh-5.3p1-94.el6.i686.rpmf00e050a86840809af4af0ed9df13cd244f94ea258844126f4ded393f75687eaELSA-2023-4428ol6_i386_latest_archive
openssh-5.3p1-94.el6.i686.rpmf00e050a86840809af4af0ed9df13cd244f94ea258844126f4ded393f75687eaELSA-2023-4428ol6_u5_i386_base
openssh-askpass-5.3p1-94.el6.i686.rpmf5f432d150e2b987849f3d9aff574df7413bce7abba4444e62fe2b78e01c74bcELSA-2023-4428ol6_i386_latest_archive
openssh-askpass-5.3p1-94.el6.i686.rpmf5f432d150e2b987849f3d9aff574df7413bce7abba4444e62fe2b78e01c74bcELSA-2023-4428ol6_u5_i386_base
openssh-clients-5.3p1-94.el6.i686.rpmcb335a40698a73676347db7d3e518cc9c2a955dfa388505faea149e0627906bbELSA-2023-4428ol6_i386_latest_archive
openssh-clients-5.3p1-94.el6.i686.rpmcb335a40698a73676347db7d3e518cc9c2a955dfa388505faea149e0627906bbELSA-2023-4428ol6_u5_i386_base
openssh-ldap-5.3p1-94.el6.i686.rpm308706e878b7a682255ac7aacbcd65c353febf51f657fa1dca4948ef1e0ab6b7ELSA-2023-4428ol6_i386_latest_archive
openssh-ldap-5.3p1-94.el6.i686.rpm308706e878b7a682255ac7aacbcd65c353febf51f657fa1dca4948ef1e0ab6b7ELSA-2023-4428ol6_u5_i386_base
openssh-server-5.3p1-94.el6.i686.rpm6a0dd27b19b87c51d83ec497f0071bbc4a1ab6ea72b3a8ff5eb2fb62d2451a8cELSA-2023-4428ol6_i386_latest_archive
openssh-server-5.3p1-94.el6.i686.rpm6a0dd27b19b87c51d83ec497f0071bbc4a1ab6ea72b3a8ff5eb2fb62d2451a8cELSA-2023-4428ol6_u5_i386_base
pam_ssh_agent_auth-0.9.3-94.el6.i686.rpmf04cc7649e5bc20ae0d97d133eaa9a258591034c60326c68fb766e1683bcf104ELSA-2023-4428ol6_i386_latest_archive
pam_ssh_agent_auth-0.9.3-94.el6.i686.rpmf04cc7649e5bc20ae0d97d133eaa9a258591034c60326c68fb766e1683bcf104ELSA-2023-4428ol6_u5_i386_base
Oracle Linux 6 (x86_64) openssh-5.3p1-94.el6.src.rpme631856adeef7872d50691131a965667c7feb4f238cc0c7c20aba2ac35e43efeELSA-2023-4428ol6_u5_x86_64_base
openssh-5.3p1-94.el6.src.rpme631856adeef7872d50691131a965667c7feb4f238cc0c7c20aba2ac35e43efeELSA-2023-4428ol6_x86_64_latest_archive
openssh-5.3p1-94.el6.x86_64.rpm65ff83f4bc31866d8ed7dc3ddb9b953d8f15084d5b2951fc3d761c994dbeb126ELSA-2023-4428ol6_u5_x86_64_base
openssh-5.3p1-94.el6.x86_64.rpm65ff83f4bc31866d8ed7dc3ddb9b953d8f15084d5b2951fc3d761c994dbeb126ELSA-2023-4428ol6_x86_64_latest_archive
openssh-askpass-5.3p1-94.el6.x86_64.rpm2a62d05ec1d73705b46d328191411cf3ec6a51de5441f857cb47ae2408b4309bELSA-2023-4428ol6_u5_x86_64_base
openssh-askpass-5.3p1-94.el6.x86_64.rpm2a62d05ec1d73705b46d328191411cf3ec6a51de5441f857cb47ae2408b4309bELSA-2023-4428ol6_x86_64_latest_archive
openssh-clients-5.3p1-94.el6.x86_64.rpmc5fd477e97a575d81b54eb2d0aae9ab527405a85e82b701a425db6e1faf5d195ELSA-2023-4428ol6_u5_x86_64_base
openssh-clients-5.3p1-94.el6.x86_64.rpmc5fd477e97a575d81b54eb2d0aae9ab527405a85e82b701a425db6e1faf5d195ELSA-2023-4428ol6_x86_64_latest_archive
openssh-ldap-5.3p1-94.el6.x86_64.rpm9bb14d29f7c3b3e7c1ee7de4cfac262569095a027876b483af38d60964fbe91cELSA-2023-4428ol6_u5_x86_64_base
openssh-ldap-5.3p1-94.el6.x86_64.rpm9bb14d29f7c3b3e7c1ee7de4cfac262569095a027876b483af38d60964fbe91cELSA-2023-4428ol6_x86_64_latest_archive
openssh-server-5.3p1-94.el6.x86_64.rpme8d30730495e8259e9cade724a8195980cdb4041878dd51ad423766ab07fdde6ELSA-2023-4428ol6_u5_x86_64_base
openssh-server-5.3p1-94.el6.x86_64.rpme8d30730495e8259e9cade724a8195980cdb4041878dd51ad423766ab07fdde6ELSA-2023-4428ol6_x86_64_latest_archive
pam_ssh_agent_auth-0.9.3-94.el6.i686.rpmf04cc7649e5bc20ae0d97d133eaa9a258591034c60326c68fb766e1683bcf104ELSA-2023-4428ol6_u5_x86_64_base
pam_ssh_agent_auth-0.9.3-94.el6.i686.rpmf04cc7649e5bc20ae0d97d133eaa9a258591034c60326c68fb766e1683bcf104ELSA-2023-4428ol6_x86_64_latest_archive
pam_ssh_agent_auth-0.9.3-94.el6.x86_64.rpm9b145337d1d558f85218519040ee71f79537661caec5fb91f21eb2dc33dcc80fELSA-2023-4428ol6_u5_x86_64_base
pam_ssh_agent_auth-0.9.3-94.el6.x86_64.rpm9b145337d1d558f85218519040ee71f79537661caec5fb91f21eb2dc33dcc80fELSA-2023-4428ol6_x86_64_latest_archive



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete