Displaying 1 result from an estimated 1 matches for "attackerrun".
2011 Aug 03
3
openssh rpm version greater than 4.3
...lain text recovery attack. The issue is in the SSH
protocol specification itself and exists in Secure Shell (SSH) software**when
used with CBC-mode ciphers.*
*OpenSSH is prone to a vulnerability that allows attackers to hijack
forwarded X connections.Successfully exploiting this issue may allow an
attackerrun arbitrary shell commands*
These are only some of the issues and they are fixed in versions 5.2 or
later.
We work with openssh src.rpm and we are interested in getting a version 5.2
or greater src.rpm from Centos. I tried compiling these rpms from openssh
source, but was unsuccessful.
Can anyone...