Unix Technical Forum

Sun SSH patch?

This is a discussion on Sun SSH patch? within the Sun Solaris Administration forums, part of the Solaris Operating System category; --> Given that Sun's sshd in Solaris 9 is based on OpenSSH, does it have the same vulnerability recently found ...


Go Back   Unix Technical Forum > Unix Operating Systems > Solaris Operating System > Sun Solaris Administration

Register FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 01-12-2008, 05:32 AM
Oscar del Rio
 
Posts: n/a
Default Sun SSH patch?

Given that Sun's sshd in Solaris 9 is based on OpenSSH,
does it have the same vulnerability recently found in OpenSSH?

Any patches in progress?

http://xforce.iss.net/xforce/alerts/id/144

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 01-12-2008, 05:33 AM
I R A Darth Aggie
 
Posts: n/a
Default Re: Sun SSH patch?

On Tue, 16 Sep 2003 21:44:55 GMT,
Oscar del Rio <delrio@mie.utoronto.ca>, in
<HLBtqv.4Jn@mie.utoronto.ca> wrote:
+> Given that Sun's sshd in Solaris 9 is based on OpenSSH,
+> does it have the same vulnerability recently found in OpenSSH?

They weren't mentioned in the CERT advisory...I don't know if that's
good, bad or indifferent!

James
--
Consulting Minister for Consultants, DNRC
I can please only one person per day. Today is not your day. Tomorrow
isn't looking good, either.
I am BOFH. Resistance is futile. Your network will be assimilated.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 01-12-2008, 05:33 AM
Akop Pogosian
 
Posts: n/a
Default Re: Sun SSH patch?

In comp.unix.solaris I R A Darth Aggie <sy_nttvr@gurcragntba.pbz> wrote:
> On Tue, 16 Sep 2003 21:44:55 GMT,
> Oscar del Rio <delrio@mie.utoronto.ca>, in
> <HLBtqv.4Jn@mie.utoronto.ca> wrote:
> +> Given that Sun's sshd in Solaris 9 is based on OpenSSH,
> +> does it have the same vulnerability recently found in OpenSSH?


> They weren't mentioned in the CERT advisory...I don't know if that's
> good, bad or indifferent!


I wouldn't automatically assume that that's good.

--
Akop Pogosian

This space has been accidentally left blank.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 01-12-2008, 05:33 AM
I R A Darth Aggie
 
Posts: n/a
Default Re: Sun SSH patch?

On Wed, 17 Sep 2003 03:04:05 +0000 (UTC),
Akop Pogosian <akopps+usenet@ocf.berkeley.edu>, in
<bk8iv5$2abe$1@agate.berkeley.edu> wrote:
+> In comp.unix.solaris I R A Darth Aggie <sy_nttvr@gurcragntba.pbz> wrote:
+> > On Tue, 16 Sep 2003 21:44:55 GMT,
+> > Oscar del Rio <delrio@mie.utoronto.ca>, in
+> > <HLBtqv.4Jn@mie.utoronto.ca> wrote:
+> > +> Given that Sun's sshd in Solaris 9 is based on OpenSSH,
+> > +> does it have the same vulnerability recently found in OpenSSH?
+>
+> > They weren't mentioned in the CERT advisory...I don't know if that's
+> > good, bad or indifferent!
+>
+> I wouldn't automatically assume that that's good.

That's what worries me...

James
--
Consulting Minister for Consultants, DNRC
I can please only one person per day. Today is not your day. Tomorrow
isn't looking good, either.
I am BOFH. Resistance is futile. Your network will be assimilated.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 01-12-2008, 05:33 AM
Seth H Holmes
 
Posts: n/a
Default Re: Sun SSH patch?

In article <slrnbmh3c2.g57.sy_nttvr@gurcragntba.pbz>, I R A Darth Aggie wrote:
> On Wed, 17 Sep 2003 03:04:05 +0000 (UTC),
> Akop Pogosian <akopps+usenet@ocf.berkeley.edu>, in
><bk8iv5$2abe$1@agate.berkeley.edu> wrote:
> +> In comp.unix.solaris I R A Darth Aggie <sy_nttvr@gurcragntba.pbz> wrote:
> +> > On Tue, 16 Sep 2003 21:44:55 GMT,
> +> > Oscar del Rio <delrio@mie.utoronto.ca>, in
> +> > <HLBtqv.4Jn@mie.utoronto.ca> wrote:
> +> > +> Given that Sun's sshd in Solaris 9 is based on OpenSSH,
> +> > +> does it have the same vulnerability recently found in OpenSSH?
> +>
> +> > They weren't mentioned in the CERT advisory...I don't know if that's
> +> > good, bad or indifferent!
> +>
> +> I wouldn't automatically assume that that's good.
>
> That's what worries me...


I've simply downloaded the source and compiled it myself.



--
Seth H Holmes

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 01-12-2008, 05:33 AM
Dave Uhring
 
Posts: n/a
Default Re: Sun SSH patch?

On Wed, 17 Sep 2003 16:36:18 +0000, I R A Darth Aggie wrote:

> On Wed, 17 Sep 2003 03:04:05 +0000 (UTC),
> Akop Pogosian <akopps+usenet@ocf.berkeley.edu>, in
> <bk8iv5$2abe$1@agate.berkeley.edu> wrote:
> +> In comp.unix.solaris I R A Darth Aggie <sy_nttvr@gurcragntba.pbz> wrote:
> +> > On Tue, 16 Sep 2003 21:44:55 GMT,
> +> > Oscar del Rio <delrio@mie.utoronto.ca>, in
> +> > <HLBtqv.4Jn@mie.utoronto.ca> wrote:
> +> > +> Given that Sun's sshd in Solaris 9 is based on OpenSSH,
> +> > +> does it have the same vulnerability recently found in OpenSSH?
> +>
> +> > They weren't mentioned in the CERT advisory...I don't know if that's
> +> > good, bad or indifferent!
> +>
> +> I wouldn't automatically assume that that's good.
>
> That's what worries me...


It should. If Sun's SSH were not vulnerable they would have issued a
notice to that effect.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 01-12-2008, 05:33 AM
Alan Coopersmith
 
Posts: n/a
Default Re: Sun SSH patch?

no-courtesy-copies-please writes in comp.unix.solaris:
|On Tue, 16 Sep 2003 21:44:55 GMT,
|Oscar del Rio <delrio@mie.utoronto.ca>, in
|<HLBtqv.4Jn@mie.utoronto.ca> wrote:
|+> Given that Sun's sshd in Solaris 9 is based on OpenSSH,
|+> does it have the same vulnerability recently found in OpenSSH?
|
|They weren't mentioned in the CERT advisory...I don't know if that's
|good, bad or indifferent!

I think it simply means CERT rushed the advisory out without waiting
for all vendors to respond. Sun has since provided a statement which
is on the CERT web page for the advisory now:
http://www.cert.org/advisories/CA-2003-24.html

--
__________________________________________________ ______________________
Alan Coopersmith alanc@alum.calberkeley.org
http://www.CSUA.Berkeley.EDU/~alanc/ aka: Alan.Coopersmith@Sun.COM
Working for, but definitely not speaking for, Sun Microsystems, Inc.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 01-12-2008, 05:33 AM
I R A Darth Aggie
 
Posts: n/a
Default Re: Sun SSH patch?

On Wed, 17 Sep 2003 21:07:15 +0000 (UTC),
Alan Coopersmith <alanc@alum.calberkeley.org>, in
<bkaie3$2vel$1@agate.berkeley.edu> wrote:
+> no-courtesy-copies-please writes in comp.unix.solaris:
+> |On Tue, 16 Sep 2003 21:44:55 GMT,
+> |Oscar del Rio <delrio@mie.utoronto.ca>, in
+> |<HLBtqv.4Jn@mie.utoronto.ca> wrote:
+> |+> Given that Sun's sshd in Solaris 9 is based on OpenSSH,
+> |+> does it have the same vulnerability recently found in OpenSSH?
+> |
+> |They weren't mentioned in the CERT advisory...I don't know if that's
+> |good, bad or indifferent!
+>
+> I think it simply means CERT rushed the advisory out without waiting
+> for all vendors to respond. Sun has since provided a statement which
+> is on the CERT web page for the advisory now:
+> http://www.cert.org/advisories/CA-2003-24.html

Yes, lots more vendors on there now...

Sun Microsystems confirms that the Solaris 9 version of Secure
Shell daemon (sshd) is affected by VU#333628. We are currently
working on a solution. A Sun Alert will be released soon that
will allow customers to track our progress on this issue.

James
--
Consulting Minister for Consultants, DNRC
I can please only one person per day. Today is not your day. Tomorrow
isn't looking good, either.
I am BOFH. Resistance is futile. Your network will be assimilated.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 01-12-2008, 05:33 AM
Philip Brown
 
Posts: n/a
Default Re: Sun SSH patch?

On Wed, 17 Sep 2003 21:07:15 +0000 (UTC), alanc@alum.calberkeley.org wrote:
>...
>I think it simply means CERT rushed the advisory out without waiting
>for all vendors to respond. Sun has since provided a statement which
>is on the CERT web page for the advisory now:
> http://www.cert.org/advisories/CA-2003-24.html


in summary: yes, it IS vulnerable.

FYI: I just put up an openssh 3.7.1p1 binary in the blastwave.org archives.
It'll get out to the mirror sites in a few hours, as usual.

WARNING: It currently is untested. If there are any problems found, I will
of course re-release the package, plus put a note on the 'news' link
from http://www.blastwave.org/packages/openssh



--
http://www.blastwave.org/ for solaris pre-packaged binaries with pkg-get
Organized by the author of pkg-get
[Trim the no-bots from my address to reply to me by email!]
S.1618 http://thomas.loc.gov/cgi-bin/bdquer...5:SN01618:@@@D
http://www.spamlaws.com/state/ca1.html
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 01-12-2008, 05:34 AM
Mr. Johan Andersson
 
Posts: n/a
Default Re: Sun SSH patch?



On Wed, 17 Sep 2003, I R A Darth Aggie wrote:

> On Tue, 16 Sep 2003 21:44:55 GMT,
> Oscar del Rio <delrio@mie.utoronto.ca>, in
> <HLBtqv.4Jn@mie.utoronto.ca> wrote:
> +> Given that Sun's sshd in Solaris 9 is based on OpenSSH,
> +> does it have the same vulnerability recently found in OpenSSH?
>
> They weren't mentioned in the CERT advisory...I don't know if that's
> good, bad or indifferent!


They are mentionen in the advisory, alert and coming solution is being
worked upon.

from advisory...
---
Sun Microsystems confirms that the Solaris 9 version of Secure Shell
daemon (sshd) is affected by VU#333628. We are currently working on a
solution. A Sun Alert will be released soon that will allow customers to
track our progress on this issue. Sun Alerts are available from
http://sunsolve.sun.com/pub-cgi/sear...egory:security
---

/Johan A

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 10:18 PM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com