Dit bericht is nog niet vertaald

[USN-597-1] OpenSSH vulnerability

Ubuntu Security Notice USN-597-1             April 01, 2008
openssh vulnerability
CVE-2008-1483
Kwetsbare Ubuntu versies:

Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
Ubuntu 7.10

Kwetsbare pakketten:

Ubuntu 6.06 LTS
openssh-client 1:4.2p1-7ubuntu3.3
Ubuntu 6.10
openssh-client 1:4.3p2-5ubuntu1.2
Ubuntu 7.10
openssh-client 1:4.6p1-5ubuntu0.2
Ubuntu 7.04
openssh-client 1:4.3p2-8ubuntu1.2

In general, a standard system upgrade is sufficient to effect the necessary changes.

Timo Juhani Lindfors discovered that the OpenSSH client, when port forwarding was requested, would listen on any available address family. A local attacker could exploit this flaw on systems with IPv6 enabled to hijack connections, including X11 forwards.