Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2007:0257 - Security Advisory
Issued:
2007-05-01
Updated:
2007-05-01

RHSA-2007:0257 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Low: openssh security and bug fix update

Type/Severity

Security Advisory: Low

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Updated openssh packages that fix a security issue and various bugs are now
available.

This update has been rated as having low security impact by the Red Hat
Security Response Team.

Description

OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. This
package includes the core files necessary for both the OpenSSH client and
server.

OpenSSH stores hostnames, IP addresses, and keys in plaintext in the
known_hosts file. A local attacker that has already compromised a user's
SSH account could use this information to generate a list of additional
targets that are likely to have the same password or key. (CVE-2005-2666)

The following bugs have also been fixed in this update:

  • The ssh client could abort the running connection when the server

application generated a large output at once.

  • When 'X11UseLocalhost' option was set to 'no' on systems with IPv6

networking enabled, the X11 forwarding socket listened only for IPv6
connections.

  • When the privilege separation was enabled in /etc/ssh/sshd_config, some

log messages in the system log were duplicated and also had timestamps from
an incorrect timezone.

All users of openssh should upgrade to these updated packages, which
contain backported patches to correct these issues.

Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:

http://www.redhat.com/docs/manuals/enterprise/

Affected Products

  • Red Hat Enterprise Linux Server 4 x86_64
  • Red Hat Enterprise Linux Server 4 ia64
  • Red Hat Enterprise Linux Server 4 i386
  • Red Hat Enterprise Linux Workstation 4 x86_64
  • Red Hat Enterprise Linux Workstation 4 ia64
  • Red Hat Enterprise Linux Workstation 4 i386
  • Red Hat Enterprise Linux Desktop 4 x86_64
  • Red Hat Enterprise Linux Desktop 4 i386
  • Red Hat Enterprise Linux for IBM z Systems 4 s390x
  • Red Hat Enterprise Linux for IBM z Systems 4 s390
  • Red Hat Enterprise Linux for Power, big endian 4 ppc

Fixes

  • BZ - 162681 - CVE-2005-2666 openssh vulnerable to known_hosts address harvesting
  • BZ - 184357 - buffer_append_space: alloc not supported Error
  • BZ - 193710 - [PATCH] audit patch for openssh missing #include "loginrec.h" in auth.c
  • BZ - 201594 - sshd does not create ipv4 listen socket for X11 forwarding
  • BZ - 203671 - additional (time skewed) log entries in /var/log/secure since U4

CVEs

  • CVE-2005-2666

References

  • http://www.redhat.com/security/updates/classification/#low
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server 4

SRPM
openssh-3.9p1-8.RHEL4.20.src.rpm SHA-256: 47b55a5c7c4cbc0773f28041a8f9aece92fa2cfe8c3a3cf3be0d635deffd63ab
x86_64
openssh-3.9p1-8.RHEL4.20.x86_64.rpm SHA-256: f8e0e6e311d75d26059a2a708974c33e725de12fa97a3931a0362cea7456d62d
openssh-3.9p1-8.RHEL4.20.x86_64.rpm SHA-256: f8e0e6e311d75d26059a2a708974c33e725de12fa97a3931a0362cea7456d62d
openssh-askpass-3.9p1-8.RHEL4.20.x86_64.rpm SHA-256: bb469412ea0b93f4e671dffc011eb8df8d92b119c5af2e27316671006b2535ea
openssh-askpass-3.9p1-8.RHEL4.20.x86_64.rpm SHA-256: bb469412ea0b93f4e671dffc011eb8df8d92b119c5af2e27316671006b2535ea
openssh-askpass-gnome-3.9p1-8.RHEL4.20.x86_64.rpm SHA-256: 1bc62b20cc9f12edbf970d1e8ef734812f45a8189b1659b0da7ac16150ec5eac
openssh-askpass-gnome-3.9p1-8.RHEL4.20.x86_64.rpm SHA-256: 1bc62b20cc9f12edbf970d1e8ef734812f45a8189b1659b0da7ac16150ec5eac
openssh-clients-3.9p1-8.RHEL4.20.x86_64.rpm SHA-256: 1927f1f927749364b12938789068bf8c3628105b6a118971dbdd2dd7d4290188
openssh-clients-3.9p1-8.RHEL4.20.x86_64.rpm SHA-256: 1927f1f927749364b12938789068bf8c3628105b6a118971dbdd2dd7d4290188
openssh-server-3.9p1-8.RHEL4.20.x86_64.rpm SHA-256: 21ee5fab87b1266a223136485cf8fffa98a30de6a07c079e07cec403a1f005f8
openssh-server-3.9p1-8.RHEL4.20.x86_64.rpm SHA-256: 21ee5fab87b1266a223136485cf8fffa98a30de6a07c079e07cec403a1f005f8
ia64
openssh-3.9p1-8.RHEL4.20.ia64.rpm SHA-256: d64f9b6c87b068f08e65d9a9051a1270bb7825e2c2aa1d344735666355c4b202
openssh-3.9p1-8.RHEL4.20.ia64.rpm SHA-256: d64f9b6c87b068f08e65d9a9051a1270bb7825e2c2aa1d344735666355c4b202
openssh-askpass-3.9p1-8.RHEL4.20.ia64.rpm SHA-256: d960fca7a237ad9ee5700dea856c8fc2664b9897b4f80a67f392d8e0c663f9ba
openssh-askpass-3.9p1-8.RHEL4.20.ia64.rpm SHA-256: d960fca7a237ad9ee5700dea856c8fc2664b9897b4f80a67f392d8e0c663f9ba
openssh-askpass-gnome-3.9p1-8.RHEL4.20.ia64.rpm SHA-256: 60721d8ba5bd301edda28efb7dfb3f18f52f70a0a6faa70561edb5c96cb4d8ae
openssh-askpass-gnome-3.9p1-8.RHEL4.20.ia64.rpm SHA-256: 60721d8ba5bd301edda28efb7dfb3f18f52f70a0a6faa70561edb5c96cb4d8ae
openssh-clients-3.9p1-8.RHEL4.20.ia64.rpm SHA-256: 44b41013bcb02f536b9ed293dc1b698e1d963c0db75f2f62f5cdda46a84d8f0a
openssh-clients-3.9p1-8.RHEL4.20.ia64.rpm SHA-256: 44b41013bcb02f536b9ed293dc1b698e1d963c0db75f2f62f5cdda46a84d8f0a
openssh-server-3.9p1-8.RHEL4.20.ia64.rpm SHA-256: 58a8f5e04b0a24fc0344a69211bf035f3f529fe6760a664dad110a26103886d3
openssh-server-3.9p1-8.RHEL4.20.ia64.rpm SHA-256: 58a8f5e04b0a24fc0344a69211bf035f3f529fe6760a664dad110a26103886d3
i386
openssh-3.9p1-8.RHEL4.20.i386.rpm SHA-256: 2d6592cf9fd819431f3b392bd3f231dd6764d12dcaf7ff5941c680bbbaa01c33
openssh-3.9p1-8.RHEL4.20.i386.rpm SHA-256: 2d6592cf9fd819431f3b392bd3f231dd6764d12dcaf7ff5941c680bbbaa01c33
openssh-askpass-3.9p1-8.RHEL4.20.i386.rpm SHA-256: 02d16941d363b9183449f0d4d04d8d06ff105792e95fa2602f056165f6e1a5e8
openssh-askpass-3.9p1-8.RHEL4.20.i386.rpm SHA-256: 02d16941d363b9183449f0d4d04d8d06ff105792e95fa2602f056165f6e1a5e8
openssh-askpass-gnome-3.9p1-8.RHEL4.20.i386.rpm SHA-256: 1a2b3e2a68d9974d9ba496beb0897f1bdefaade35f747ba359d42008e6f8f271
openssh-askpass-gnome-3.9p1-8.RHEL4.20.i386.rpm SHA-256: 1a2b3e2a68d9974d9ba496beb0897f1bdefaade35f747ba359d42008e6f8f271
openssh-clients-3.9p1-8.RHEL4.20.i386.rpm SHA-256: 44f427df41b55ed7d46a4198a8e103e050850f6ae84e745b239557db950fd2fe
openssh-clients-3.9p1-8.RHEL4.20.i386.rpm SHA-256: 44f427df41b55ed7d46a4198a8e103e050850f6ae84e745b239557db950fd2fe
openssh-server-3.9p1-8.RHEL4.20.i386.rpm SHA-256: c9fbb91d715a1cdd8296576de0af764abbd33f75093a4ea177a634f1512dd702
openssh-server-3.9p1-8.RHEL4.20.i386.rpm SHA-256: c9fbb91d715a1cdd8296576de0af764abbd33f75093a4ea177a634f1512dd702

Red Hat Enterprise Linux Workstation 4

SRPM
openssh-3.9p1-8.RHEL4.20.src.rpm SHA-256: 47b55a5c7c4cbc0773f28041a8f9aece92fa2cfe8c3a3cf3be0d635deffd63ab
x86_64
openssh-3.9p1-8.RHEL4.20.x86_64.rpm SHA-256: f8e0e6e311d75d26059a2a708974c33e725de12fa97a3931a0362cea7456d62d
openssh-askpass-3.9p1-8.RHEL4.20.x86_64.rpm SHA-256: bb469412ea0b93f4e671dffc011eb8df8d92b119c5af2e27316671006b2535ea
openssh-askpass-gnome-3.9p1-8.RHEL4.20.x86_64.rpm SHA-256: 1bc62b20cc9f12edbf970d1e8ef734812f45a8189b1659b0da7ac16150ec5eac
openssh-clients-3.9p1-8.RHEL4.20.x86_64.rpm SHA-256: 1927f1f927749364b12938789068bf8c3628105b6a118971dbdd2dd7d4290188
openssh-server-3.9p1-8.RHEL4.20.x86_64.rpm SHA-256: 21ee5fab87b1266a223136485cf8fffa98a30de6a07c079e07cec403a1f005f8
ia64
openssh-3.9p1-8.RHEL4.20.ia64.rpm SHA-256: d64f9b6c87b068f08e65d9a9051a1270bb7825e2c2aa1d344735666355c4b202
openssh-askpass-3.9p1-8.RHEL4.20.ia64.rpm SHA-256: d960fca7a237ad9ee5700dea856c8fc2664b9897b4f80a67f392d8e0c663f9ba
openssh-askpass-gnome-3.9p1-8.RHEL4.20.ia64.rpm SHA-256: 60721d8ba5bd301edda28efb7dfb3f18f52f70a0a6faa70561edb5c96cb4d8ae
openssh-clients-3.9p1-8.RHEL4.20.ia64.rpm SHA-256: 44b41013bcb02f536b9ed293dc1b698e1d963c0db75f2f62f5cdda46a84d8f0a
openssh-server-3.9p1-8.RHEL4.20.ia64.rpm SHA-256: 58a8f5e04b0a24fc0344a69211bf035f3f529fe6760a664dad110a26103886d3
i386
openssh-3.9p1-8.RHEL4.20.i386.rpm SHA-256: 2d6592cf9fd819431f3b392bd3f231dd6764d12dcaf7ff5941c680bbbaa01c33
openssh-askpass-3.9p1-8.RHEL4.20.i386.rpm SHA-256: 02d16941d363b9183449f0d4d04d8d06ff105792e95fa2602f056165f6e1a5e8
openssh-askpass-gnome-3.9p1-8.RHEL4.20.i386.rpm SHA-256: 1a2b3e2a68d9974d9ba496beb0897f1bdefaade35f747ba359d42008e6f8f271
openssh-clients-3.9p1-8.RHEL4.20.i386.rpm SHA-256: 44f427df41b55ed7d46a4198a8e103e050850f6ae84e745b239557db950fd2fe
openssh-server-3.9p1-8.RHEL4.20.i386.rpm SHA-256: c9fbb91d715a1cdd8296576de0af764abbd33f75093a4ea177a634f1512dd702

Red Hat Enterprise Linux Desktop 4

SRPM
openssh-3.9p1-8.RHEL4.20.src.rpm SHA-256: 47b55a5c7c4cbc0773f28041a8f9aece92fa2cfe8c3a3cf3be0d635deffd63ab
x86_64
openssh-3.9p1-8.RHEL4.20.x86_64.rpm SHA-256: f8e0e6e311d75d26059a2a708974c33e725de12fa97a3931a0362cea7456d62d
openssh-askpass-3.9p1-8.RHEL4.20.x86_64.rpm SHA-256: bb469412ea0b93f4e671dffc011eb8df8d92b119c5af2e27316671006b2535ea
openssh-askpass-gnome-3.9p1-8.RHEL4.20.x86_64.rpm SHA-256: 1bc62b20cc9f12edbf970d1e8ef734812f45a8189b1659b0da7ac16150ec5eac
openssh-clients-3.9p1-8.RHEL4.20.x86_64.rpm SHA-256: 1927f1f927749364b12938789068bf8c3628105b6a118971dbdd2dd7d4290188
openssh-server-3.9p1-8.RHEL4.20.x86_64.rpm SHA-256: 21ee5fab87b1266a223136485cf8fffa98a30de6a07c079e07cec403a1f005f8
i386
openssh-3.9p1-8.RHEL4.20.i386.rpm SHA-256: 2d6592cf9fd819431f3b392bd3f231dd6764d12dcaf7ff5941c680bbbaa01c33
openssh-askpass-3.9p1-8.RHEL4.20.i386.rpm SHA-256: 02d16941d363b9183449f0d4d04d8d06ff105792e95fa2602f056165f6e1a5e8
openssh-askpass-gnome-3.9p1-8.RHEL4.20.i386.rpm SHA-256: 1a2b3e2a68d9974d9ba496beb0897f1bdefaade35f747ba359d42008e6f8f271
openssh-clients-3.9p1-8.RHEL4.20.i386.rpm SHA-256: 44f427df41b55ed7d46a4198a8e103e050850f6ae84e745b239557db950fd2fe
openssh-server-3.9p1-8.RHEL4.20.i386.rpm SHA-256: c9fbb91d715a1cdd8296576de0af764abbd33f75093a4ea177a634f1512dd702

Red Hat Enterprise Linux for IBM z Systems 4

SRPM
openssh-3.9p1-8.RHEL4.20.src.rpm SHA-256: 47b55a5c7c4cbc0773f28041a8f9aece92fa2cfe8c3a3cf3be0d635deffd63ab
s390x
openssh-3.9p1-8.RHEL4.20.s390x.rpm SHA-256: 43463217ac7ec80da3259b74d20508dea1c6dabedf65a2a2928346b3bdd71d5e
openssh-askpass-3.9p1-8.RHEL4.20.s390x.rpm SHA-256: 2877dc01cff7828671448f84363d64d831ddba087dd3bd11cc641ba022ea762a
openssh-askpass-gnome-3.9p1-8.RHEL4.20.s390x.rpm SHA-256: a8f1d35ac3f1af67c2458e2b643124ab3c74caecb7bcfad9a8bd5f1ff4af181d
openssh-clients-3.9p1-8.RHEL4.20.s390x.rpm SHA-256: 05950ef233d88c291a258da37ea444c7c7200505b7970ca3154f5ea490eb7002
openssh-server-3.9p1-8.RHEL4.20.s390x.rpm SHA-256: bf5b63550b88ce27346287c54bc30d67c0b74515a4c1a48572d7d5871e22d2c3
s390
openssh-3.9p1-8.RHEL4.20.s390.rpm SHA-256: cce045c36dc17e1745bb11d355d35fd3d5e5835d356ae88e05183985ed8ef430
openssh-askpass-3.9p1-8.RHEL4.20.s390.rpm SHA-256: 1adbc11481043d4389fec32bc7b1829caf31302674ef58eefea0abd81ee2d56d
openssh-askpass-gnome-3.9p1-8.RHEL4.20.s390.rpm SHA-256: 605be9b90f37893c43df72ccf392c6517295328ad39faa4c11afa49dd749d332
openssh-clients-3.9p1-8.RHEL4.20.s390.rpm SHA-256: b47b2dd597472d18d7da929c3cb5d153bf1338e83dd66c1787e5e3ae8e86b241
openssh-server-3.9p1-8.RHEL4.20.s390.rpm SHA-256: 548ac3a39b65990d33eddd7808dc5a61fea8afa53151e8451d352ad45ff980e4

Red Hat Enterprise Linux for Power, big endian 4

SRPM
openssh-3.9p1-8.RHEL4.20.src.rpm SHA-256: 47b55a5c7c4cbc0773f28041a8f9aece92fa2cfe8c3a3cf3be0d635deffd63ab
ppc
openssh-3.9p1-8.RHEL4.20.ppc.rpm SHA-256: d7fc38299d2ef2af7c61b53e32571c3d0f4ef09b0864b50078e5b946ace53a50
openssh-askpass-3.9p1-8.RHEL4.20.ppc.rpm SHA-256: 4f22a943853c26bfcd4a057cbd3c2bc876f664a6fc976dac2851b3d94ccbb7d1
openssh-askpass-gnome-3.9p1-8.RHEL4.20.ppc.rpm SHA-256: 12a485bb13a73e8d04eedf63ff78788c59e9039df49c092b44cea4d81bbda59b
openssh-clients-3.9p1-8.RHEL4.20.ppc.rpm SHA-256: 7df9057a52b0bb54b024904d78afe3998726ee7eb4a7078b9113817d34b92edc
openssh-server-3.9p1-8.RHEL4.20.ppc.rpm SHA-256: 2c110201f1c10bb51660c843a0cbe5d6aa0c112a652b6df77f5ff3f8589358eb

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility