1832642 Members
2827 Online
110043 Solutions
New Discussion

OpenSSH bug

 
jmb
Regular Advisor

OpenSSH bug

This has just been reported in the last day or so (trusecure). Does anyone know how/if this affects the HP ports?
10 REPLIES 10
Steven E. Protter
Exalted Contributor

Re: OpenSSH bug

HP Secure Shell Version 3.50 is based on Openssh 3.5.

Any bug found in openssh v 3.5.x is likely to affect HP's version, unless HP caught it and corrected it during the port.

It would be safe to assume that if HP found and corrected the bug they'd have reported it.

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
John Henrikson
Regular Advisor

Re: OpenSSH bug

The latest version on software.hp.com is
HP-UX Secure Shell A.03.61.001
posted only a few days ago..
I too need to know if this fixes the recent bug or if they'll need to patch it..
thanks!
John H.
Berlene Herren
Honored Contributor

Re: OpenSSH bug

Hello Everyone concerned about this bug... I have asked our security-alert team and they are investigating. I will post their answer as soon as I get it, unless they post before then :-)

Regards,
Berlene
http://www.mindspring.com/~bkherren/dobes/index.htm
Steven E. Protter
Exalted Contributor

Re: OpenSSH bug

If there is a bug found in whatever version of HP openssh that Secure Shell has been based on, it is very likely to be in HP's port as well.

Staying tuned for Berlene's next post.

Thread owner: please pop Berlene some points, just for being our communities security hawk.

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
Duncan Ball
Occasional Advisor

Re: OpenSSH bug

Hi all,

FYI, version 3.7 of openssh has just been released. Berlene, will HP be generating a depot based on this release?

Duncan Ball
Steven E. Protter
Exalted Contributor

Re: OpenSSH bug

HP takes its time to do ports of openssh. That is good for quality control.

Since 3.6 just came out, I think it highly unlikely that 3.7 is going to come out quickly.

Thanks to the author for the points. Much appreciated.

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
Berlene Herren
Honored Contributor

Re: OpenSSH bug

Duncan, all I can say is that HP is investigating this issue and will release a security bulletin concerning it if found that our porting of Openssh is vulnerable.

Thanks and stay tuned! I'll get it out hot off of the press... whoever is subscribed to the security bulletins will get it about the same time :-)

To subscribe to automatically receive future NEW HP Security
Bulletins from the HP IT Resource Center via electronic
mail, do the following:

Use your browser to get to the HP IT Resource Center page
at:

http://itrc.hp.com

Use the 'Login' tab at the left side of the screen to login
using your ID and password. Use your existing login or the
"Register" button at the left to create a login, in order to
gain access to many areas of the ITRC. Remember to save the
User ID assigned to you, and your password.

In the left most frame select "Maintenance and Support".

Under the "Notifications" section (near the bottom of
the page), select "Support Information Digests".

To -subscribe- to future HP Security Bulletins or other
Technical Digests, click the check box (in the left column)
for the appropriate digest and then click the "Update
Subscriptions" button at the bottom of the page.

or

To -review- bulletins already released, select the link
(in the middle column) for the appropriate digest.

NOTE: Using your itrc account security bulletins can be
found here:
http://itrc.hp.com/cki/bin/doc.pl/screen=ckiSecurityBulletin


To -gain access- to the Security Patch Matrix, select
the link for "The Security Bulletins Archive". (near the
bottom of the page) Once in the archive the third link is
to the current Security Patch Matrix. Updated daily, this
matrix categorizes security patches by platform/OS release,
and by bulletin topic. Security Patch Check completely
automates the process of reviewing the patch matrix for
11.XX systems. Please note that installing the patches
listed in the Security Patch Matrix will completely
implement a security bulletin _only_ if the MANUAL ACTIONS
field specifies "No."

The Security Patch Check tool can verify that a security
bulletin has been implemented on HP-UX 11.XX systems providing
that the fix is completely implemented in a patch with no
manual actions required. The Security Patch Check tool cannot
verify fixes implemented via a product upgrade.

For information on the Security Patch Check tool, see:
http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/
displayProductInfo.pl?productNumber=B6834AA

The security patch matrix is also available via anonymous
ftp:

ftp://ftp.itrc.hp.com/export/patches/hp-ux_patch_matrix/

On the "Support Information Digest Main" page:
click on the "HP Security Bulletin Archive".

The PGP key used to sign this bulletin is available from
several PGP Public Key servers. The key identification
information is:

2D2A7D59
HP Security Response Team (Security Bulletin signing only)

Fingerprint =
6002 6019 BFC1 BC62 F079 862E E01F 3AFC 2D2A 7D59

If you have problems locating the key please write to
security-alert@hp.com. Please note that this key is
for signing bulletins only and is not the key returned
by sending 'get key' to security-alert@hp.com.


D. To report new security vulnerabilities, send email to

security-alert@hp.com


Berlene

http://www.mindspring.com/~bkherren/dobes/index.htm
jmb
Regular Advisor

Re: OpenSSH bug

This is now Friday morning. Someone in the field at HP had indicated to me there would be a patch for this posted by now. Perhaps that info was not correct? I just received the HP-UX security bulletins digest from yesterday, but there is no mention of anything for ssh (or sendmail) in it. Should I be expecting a patch in weeks, rather than days?
jmb
Regular Advisor

Re: OpenSSH bug

This is now Friday morning. Someone in the field at HP had indicated to me there would be a patch for this posted by now. Perhaps that info was not correct? I just received the HP-UX security bulletins digest from yesterday, but there is no mention of anything for ssh (or sendmail) in it. Should I be expecting a patch in weeks, rather than days?
John Morris
Advisor

Re: OpenSSH bug

All we can say is that the issue is being worked with the highest priority. When a solution is available a security bulletin will be released.

Yours truly,
John Morris
HP SOFTWARE SECURITY RESPONSE TEAM (SSRT)