<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OpenSSH bug in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072367#M141027</link>
    <description>HP Secure Shell Version 3.50 is based on Openssh 3.5.&lt;BR /&gt;&lt;BR /&gt;Any bug found in openssh v 3.5.x is likely to affect HP's version, unless HP caught it and corrected it during the port.&lt;BR /&gt;&lt;BR /&gt;It would be safe to assume that if HP found and corrected the bug they'd have reported it.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
    <pubDate>Tue, 16 Sep 2003 14:53:56 GMT</pubDate>
    <dc:creator>Steven E. Protter</dc:creator>
    <dc:date>2003-09-16T14:53:56Z</dc:date>
    <item>
      <title>OpenSSH bug</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072366#M141026</link>
      <description>This has just been reported in the last day or so (trusecure).  Does anyone know how/if this affects the HP ports?</description>
      <pubDate>Tue, 16 Sep 2003 14:45:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072366#M141026</guid>
      <dc:creator>jmb</dc:creator>
      <dc:date>2003-09-16T14:45:37Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSH bug</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072367#M141027</link>
      <description>HP Secure Shell Version 3.50 is based on Openssh 3.5.&lt;BR /&gt;&lt;BR /&gt;Any bug found in openssh v 3.5.x is likely to affect HP's version, unless HP caught it and corrected it during the port.&lt;BR /&gt;&lt;BR /&gt;It would be safe to assume that if HP found and corrected the bug they'd have reported it.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 16 Sep 2003 14:53:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072367#M141027</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2003-09-16T14:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSH bug</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072368#M141028</link>
      <description>The latest version on software.hp.com is &lt;BR /&gt;HP-UX Secure Shell A.03.61.001 &lt;BR /&gt;posted only a few days ago.. &lt;BR /&gt;I too need to know if this fixes the recent bug or if they'll need to patch it.. &lt;BR /&gt;thanks! &lt;BR /&gt;John H. &lt;BR /&gt;</description>
      <pubDate>Tue, 16 Sep 2003 15:37:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072368#M141028</guid>
      <dc:creator>John Henrikson</dc:creator>
      <dc:date>2003-09-16T15:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSH bug</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072369#M141029</link>
      <description>Hello Everyone concerned about this bug... I have asked our security-alert team and they are investigating.  I will post their answer as soon as I get it, unless they post before then :-)&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Berlene</description>
      <pubDate>Tue, 16 Sep 2003 17:55:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072369#M141029</guid>
      <dc:creator>Berlene Herren</dc:creator>
      <dc:date>2003-09-16T17:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSH bug</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072370#M141030</link>
      <description>If there is a bug found in whatever version of HP  openssh that Secure Shell has been based on, it is very likely to be in HP's port as well.&lt;BR /&gt;&lt;BR /&gt;Staying tuned for Berlene's next post. &lt;BR /&gt;&lt;BR /&gt;Thread owner: please pop Berlene some points, just for being our communities security hawk.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 16 Sep 2003 18:24:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072370#M141030</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2003-09-16T18:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSH bug</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072371#M141031</link>
      <description>Hi all,&lt;BR /&gt;&lt;BR /&gt;FYI, version 3.7 of openssh has just been released. Berlene, will HP be generating a depot based on this release?&lt;BR /&gt;&lt;BR /&gt;Duncan Ball</description>
      <pubDate>Wed, 17 Sep 2003 01:01:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072371#M141031</guid>
      <dc:creator>Duncan Ball</dc:creator>
      <dc:date>2003-09-17T01:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSH bug</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072372#M141032</link>
      <description>HP takes its time to do ports of openssh.  That is good for quality control.&lt;BR /&gt;&lt;BR /&gt;Since 3.6 just came out, I think it highly unlikely that 3.7 is going to come out quickly.  &lt;BR /&gt;&lt;BR /&gt;Thanks to the author for the points.  Much appreciated.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Wed, 17 Sep 2003 04:18:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072372#M141032</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2003-09-17T04:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSH bug</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072373#M141033</link>
      <description>Duncan, all I can say is that HP is investigating this issue and will release a security bulletin concerning it if found that our porting of Openssh is vulnerable.&lt;BR /&gt;&lt;BR /&gt;Thanks and stay tuned!  I'll get it out hot off of the press... whoever is subscribed to the security bulletins will get it about the same time :-)&lt;BR /&gt;&lt;BR /&gt;   To subscribe to automatically receive future NEW HP Security&lt;BR /&gt;    Bulletins from the HP IT Resource Center via electronic&lt;BR /&gt;    mail, do the following:&lt;BR /&gt;&lt;BR /&gt;    Use your browser to get to the HP IT Resource Center page&lt;BR /&gt;    at:&lt;BR /&gt;&lt;BR /&gt;       &lt;A href="http://itrc.hp.com" target="_blank"&gt;http://itrc.hp.com&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;    Use the 'Login' tab at the left side of the screen to login&lt;BR /&gt;    using your ID and password.  Use your existing login or the&lt;BR /&gt;    "Register" button at the left to create a login, in order to&lt;BR /&gt;    gain access to many areas of the ITRC.  Remember to save the&lt;BR /&gt;    User ID assigned to you, and your password.&lt;BR /&gt;&lt;BR /&gt;    In the left most frame select "Maintenance and Support".&lt;BR /&gt;&lt;BR /&gt;    Under the "Notifications" section (near the bottom of&lt;BR /&gt;    the page), select "Support Information Digests".&lt;BR /&gt;&lt;BR /&gt;    To -subscribe- to future HP Security Bulletins or other&lt;BR /&gt;    Technical Digests, click the check box (in the left column)&lt;BR /&gt;    for the appropriate digest and then click the "Update&lt;BR /&gt;    Subscriptions" button at the bottom of the page.&lt;BR /&gt;&lt;BR /&gt;    or&lt;BR /&gt;&lt;BR /&gt;    To -review- bulletins already released, select the link&lt;BR /&gt;    (in the middle column) for the appropriate digest.&lt;BR /&gt;&lt;BR /&gt;    NOTE: Using your itrc account security bulletins can be&lt;BR /&gt;          found here:&lt;BR /&gt;    &lt;A href="http://itrc.hp.com/cki/bin/doc.pl/screen=ckiSecurityBulletin" target="_blank"&gt;http://itrc.hp.com/cki/bin/doc.pl/screen=ckiSecurityBulletin&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;    To -gain access- to the Security Patch Matrix, select&lt;BR /&gt;    the link for "The Security Bulletins Archive".  (near the&lt;BR /&gt;    bottom of the page)  Once in the archive the third link is&lt;BR /&gt;    to the current Security Patch Matrix. Updated daily, this&lt;BR /&gt;    matrix categorizes security patches by platform/OS release,&lt;BR /&gt;    and by bulletin topic.  Security Patch Check completely&lt;BR /&gt;    automates the process of reviewing the patch matrix for&lt;BR /&gt;    11.XX systems.  Please note that installing the patches&lt;BR /&gt;    listed in the Security Patch Matrix will completely&lt;BR /&gt;    implement a security bulletin _only_ if the MANUAL ACTIONS&lt;BR /&gt;    field specifies "No."&lt;BR /&gt;&lt;BR /&gt;    The Security Patch Check tool can verify that a security&lt;BR /&gt;    bulletin has been implemented on HP-UX 11.XX systems providing&lt;BR /&gt;    that the fix is completely implemented in a patch with no&lt;BR /&gt;    manual actions required.  The Security Patch Check tool cannot&lt;BR /&gt;    verify fixes implemented via a product upgrade.&lt;BR /&gt;&lt;BR /&gt;    For information on the Security Patch Check tool, see:&lt;BR /&gt;    &lt;A href="http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/" target="_blank"&gt;http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/&lt;/A&gt;&lt;BR /&gt;    displayProductInfo.pl?productNumber=B6834AA&lt;BR /&gt;&lt;BR /&gt;    The security patch matrix is also available via anonymous&lt;BR /&gt;    ftp:&lt;BR /&gt;&lt;BR /&gt;    &lt;A href="ftp://ftp.itrc.hp.com/export/patches/hp-ux_patch_matrix/" target="_blank"&gt;ftp://ftp.itrc.hp.com/export/patches/hp-ux_patch_matrix/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;    On the "Support Information Digest Main" page:&lt;BR /&gt;    click on the "HP Security Bulletin Archive".&lt;BR /&gt;&lt;BR /&gt;    The PGP key used to sign this bulletin is available from&lt;BR /&gt;    several PGP Public Key servers.  The key identification&lt;BR /&gt;    information is:&lt;BR /&gt;&lt;BR /&gt;       2D2A7D59&lt;BR /&gt;       HP Security Response Team (Security Bulletin signing only)&lt;BR /&gt;&lt;BR /&gt;       Fingerprint =&lt;BR /&gt;         6002 6019 BFC1 BC62 F079 862E E01F 3AFC 2D2A 7D59&lt;BR /&gt;&lt;BR /&gt;    If you have problems locating the key please write to&lt;BR /&gt;    security-alert@hp.com.  Please note that this key is&lt;BR /&gt;    for signing bulletins only and is not the key returned&lt;BR /&gt;    by sending 'get key' to security-alert@hp.com.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt; D. To report new security vulnerabilities, send email to&lt;BR /&gt;&lt;BR /&gt;    security-alert@hp.com&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Berlene&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 17 Sep 2003 10:02:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072373#M141033</guid>
      <dc:creator>Berlene Herren</dc:creator>
      <dc:date>2003-09-17T10:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSH bug</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072374#M141034</link>
      <description>This is now Friday morning.  Someone in the field at HP had indicated to me there would be a patch for this posted by now.  Perhaps that info was not correct?  I just received the HP-UX security bulletins digest from yesterday, but there is no mention of anything for ssh (or sendmail) in it.  Should I be expecting a patch in weeks, rather than days?</description>
      <pubDate>Fri, 19 Sep 2003 14:56:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072374#M141034</guid>
      <dc:creator>jmb</dc:creator>
      <dc:date>2003-09-19T14:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSH bug</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072375#M141035</link>
      <description>This is now Friday morning.  Someone in the field at HP had indicated to me there would be a patch for this posted by now.  Perhaps that info was not correct?  I just received the HP-UX security bulletins digest from yesterday, but there is no mention of anything for ssh (or sendmail) in it.  Should I be expecting a patch in weeks, rather than days?</description>
      <pubDate>Fri, 19 Sep 2003 14:56:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072375#M141035</guid>
      <dc:creator>jmb</dc:creator>
      <dc:date>2003-09-19T14:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSH bug</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072376#M141036</link>
      <description>All we can say is that the issue is being worked with the highest priority. When a solution is available a security bulletin will be released.  &lt;BR /&gt;&lt;BR /&gt;Yours truly,&lt;BR /&gt;John Morris&lt;BR /&gt;HP SOFTWARE SECURITY RESPONSE TEAM (SSRT)&lt;BR /&gt;</description>
      <pubDate>Fri, 19 Sep 2003 15:49:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/openssh-bug/m-p/3072376#M141036</guid>
      <dc:creator>John Morris</dc:creator>
      <dc:date>2003-09-19T15:49:56Z</dc:date>
    </item>
  </channel>
</rss>

