| Description: | The remote host is missing an update to openssh announced via advisory USN-597-1.
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS Ubuntu 6.10 Ubuntu 7.04 Ubuntu 7.10
This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.
Details follow:
Timo Juhani Lindfors discovered that the OpenSSH client, when port forwarding was requested, would listen on any available address script_family(. A local attacker could exploit this flaw on systems with IPv6 enabled to hijack connections, including X11 forwards.
Solution: The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 6.06 LTS: openssh-client 1:4.2p1-7ubuntu3.3
Ubuntu 6.10: openssh-client 1:4.3p2-5ubuntu1.2
Ubuntu 7.04: openssh-client 1:4.3p2-8ubuntu1.2
Ubuntu 7.10: openssh-client 1:4.6p1-5ubuntu0.2
In general, a standard system upgrade is sufficient to effect the necessary changes.
http://www.securityspace.com/smysecure/catid.html?in=USN-597-1
Risk factor : High |