<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ssh vulneribility in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-vulneribility/m-p/3871680#M739178</link>
    <description>Hi Thomas, &lt;BR /&gt;&lt;BR /&gt;Latest version for Secure shell available from HP is, A.04.30.014. It should fix the security hole. &lt;BR /&gt;&lt;BR /&gt;And, there is no downtime required to install Secure shell. Older SSH connection will remain the same untill reconnected. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;URL : &lt;A href="http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=T1471AA" target="_blank"&gt;http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=T1471AA&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;-Arun</description>
    <pubDate>Thu, 28 Sep 2006 10:42:09 GMT</pubDate>
    <dc:creator>Arunvijai_4</dc:creator>
    <dc:date>2006-09-28T10:42:09Z</dc:date>
    <item>
      <title>ssh vulneribility</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-vulneribility/m-p/3871679#M739177</link>
      <description>we have this note from security...&lt;BR /&gt;OpenSSH GSSAPI Credential Disclosure Vulnerability &lt;BR /&gt;&lt;BR /&gt;  156.99.4.5 (-, -)  port 22/tcp HP-UX 11 CVSS:  -  Active &lt;BR /&gt;&lt;BR /&gt;SOLUTION:&lt;BR /&gt;This issue affects versions of OpenSSH prior to 4.2. The vendor released OpenSSH version 4.2 to address this issue. &lt;BR /&gt;&lt;BR /&gt;so will the upgrade help, if so what would be the steps and would it require a downtime as this is a prod box. Also if i upgrade will it fix this issue?&lt;BR /&gt;&lt;BR /&gt;Please advise&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;Thomas</description>
      <pubDate>Thu, 28 Sep 2006 10:38:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-vulneribility/m-p/3871679#M739177</guid>
      <dc:creator>M.Thomas</dc:creator>
      <dc:date>2006-09-28T10:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: ssh vulneribility</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-vulneribility/m-p/3871680#M739178</link>
      <description>Hi Thomas, &lt;BR /&gt;&lt;BR /&gt;Latest version for Secure shell available from HP is, A.04.30.014. It should fix the security hole. &lt;BR /&gt;&lt;BR /&gt;And, there is no downtime required to install Secure shell. Older SSH connection will remain the same untill reconnected. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;URL : &lt;A href="http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=T1471AA" target="_blank"&gt;http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=T1471AA&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;-Arun</description>
      <pubDate>Thu, 28 Sep 2006 10:42:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-vulneribility/m-p/3871680#M739178</guid>
      <dc:creator>Arunvijai_4</dc:creator>
      <dc:date>2006-09-28T10:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: ssh vulneribility</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-vulneribility/m-p/3871681#M739179</link>
      <description>Arun:&lt;BR /&gt;&lt;BR /&gt;so just swinstall the new depot file and we are done. nothing to change? that sounds so simple. please confirm, this is a production box&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;Thomas</description>
      <pubDate>Thu, 28 Sep 2006 11:02:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-vulneribility/m-p/3871681#M739179</guid>
      <dc:creator>M.Thomas</dc:creator>
      <dc:date>2006-09-28T11:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: ssh vulneribility</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-vulneribility/m-p/3871682#M739180</link>
      <description>Hi Thomas, &lt;BR /&gt;&lt;BR /&gt;Yes, Just swinstall will be fine. It is better you go through the release notes for secure shell, &lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://docs.hp.com/en/internet.html#Secure%20Shell" target="_blank"&gt;http://docs.hp.com/en/internet.html#Secure%20Shell&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;-Arun</description>
      <pubDate>Thu, 28 Sep 2006 11:14:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-vulneribility/m-p/3871682#M739180</guid>
      <dc:creator>Arunvijai_4</dc:creator>
      <dc:date>2006-09-28T11:14:20Z</dc:date>
    </item>
  </channel>
</rss>

