RHEL 3 and OpenSSH question..

 
Thread Tools Search this Thread
Operating Systems Linux Red Hat RHEL 3 and OpenSSH question..
# 1  
Old 04-26-2012
RHEL 3 and OpenSSH question..

Hey Folks,

I currently have several RHEL 3 machines. All of them are running OpenSSH_3.6.1p2, SSH protocols 1.5/2.0

I have a vulnerability issue and need to update OpenSSH to the newest version supported by RHEL 3.

The question is:

What would that version would be?

This is actually the problem:


"OpenSSH is a set of computer programs that provides encrypted communication sessions over a computer network using the ssh protocol. OpenSSH includes Pluggable Authentication Module (PAM) which depends on text configuration files for security actions to be taken for an application. A remote administrator user account guessing vulnerability is present in OpenSSH editions. If PermitRootLogin is disabled, a remote attacker can guess the administrator password through a timing attack. A successful exploitation will allow the attacker to guess the root password."


Thanks!Smilie

Last edited by 300zxmuro; 04-26-2012 at 03:24 PM..
# 2  
Old 04-27-2012
I don't think RHEL 3 is supported anymore. What exact vulnerability are you talking about?

By the way, my RHEL 6.2 box carries this version of OpenSSH (client and server)
Code:
# rpm -qa | grep ssh
openssh-clients-5.3p1-70.el6.x86_64
libssh2-1.2.2-7.el6_1.1.x86_64
openssh-server-5.3p1-70.el6.x86_64
openssh-5.3p1-70.el6.x86_64

Login or Register to Ask a Question

Previous Thread | Next Thread

10 More Discussions You Might Find Interesting

1. AIX

Question about shared filesystem btw AIX and RHEL

We found out that the Spectrum Scale (GPFS) doesnt support mix nodes (AIX and RHEL) on direct attached storage. Is there any other options besides NFS for mix O/S? Trying to avoid network type of shared filesystem which might end up high traffic on IO because we do run backup jobs on those... (0 Replies)
Discussion started by: kiasu
0 Replies

2. Red Hat

RHEL 6, Spacewalk 2.3 unable to download RHEL 5 repo data

Hello all, I am having a bit of an issue on my Spacewalk installation. Some amplifying information is that it is Spacewalk 2.3 installed on a RHEL 6 machine and I am attempting to install/update a RHEL 5 channel/repository. I am fairly new to Spacewalk so I am still learning but this is what I... (3 Replies)
Discussion started by: jstone4646
3 Replies

3. Red Hat

RHEL 6 Certification Question (sorry)

:b:Hi Linux People, Apologies, but its yet another RHCSA/RHCE (RHEL 6) question. I simply need to know what I will be faced with when I click 'Start Exam' for both of these certs. I have passed multiple 'multi-choice' exams in the past in Microsoft, COMPTIA, Oracle Solaris, etc, etc, etc. ... (1 Reply)
Discussion started by: patcom
1 Replies

4. Red Hat

Vulnerability with ssh in OpenSSH in an RHEL installation

There was a security analysis run on one server which has RHEL 5.8 installed and it is showing security vulnerabilities with respect to ssh in OpenSSH with reference no CVE-2007-4752. The vulnerability solution in the security report is showing solution as below: 1) Download and apply the... (3 Replies)
Discussion started by: RHCE
3 Replies

5. Red Hat

Installing OPENSSH 6.2P2 on RHEL 4, 64B failed

make: Leaving directory `/u01/openssh-6.2p2/openbsd-compat' gcc -g -O2 -Wall -Wpointer-arith -Wuninitialized -Wsign-compare -Wformat-security -fno-strict-aliasing -D_FORTIFY_SOURCE=2 -fno-builtin-memset -std=gnu99 -I. -I. -DSSHDIR=\"/usr/local/etc\" - D_PATH_SSH_PROGRAM=\"/usr/local/bin/ssh\"... (0 Replies)
Discussion started by: scao
0 Replies

6. Red Hat

Error throwing while installing vsftpd package in rhel 6. using rhel 6 dvd.

Hi all, Im studying rhcsa as of now, so yum installation and dependencies are messing me to not workit out. i have dual os, win 7 & rhel 6. i have tried this installation of vsftpd package with rhel 6 dvd in VM rhel 6 in win 7 as well as host rhel 6.still the same issue. below error... (6 Replies)
Discussion started by: redhatlbug
6 Replies

7. Red Hat

Does RHEL 5 provide a command to collect RHEL system log in single compress file?

Hi, I heard a command that can collect all RHEL 5 log in a single compress file before I forget. Does any body know...What the command is ? Thanks. (4 Replies)
Discussion started by: nnnnnnine
4 Replies

8. Red Hat

RHEL Certification Question

Hi RedHat Enterprise users. Does anyone know if the new RHCSA and also the RHCE exams can be taken via independent, self-study? By this I mean not attending an offical RedHat certification course and arranging the exams myself. Many thanks for your time. (2 Replies)
Discussion started by: patcom
2 Replies

9. UNIX for Dummies Questions & Answers

OpenSSH Configuration Question

In sshd_config it is written: # The strategy used for options in the default sshd_config shipped with # OpenSSH is to specify options with their default value where # possible, but leave them commented. Uncommented options change a # default value. So does that mean for the following: ... (2 Replies)
Discussion started by: mojoman
2 Replies

10. UNIX for Dummies Questions & Answers

Question about Openssh and sftp

I have to create an automated sftp job on an AIX box. The sftp command doesnt work. Do I need to install the openssh package in order to be able to invoke the sftp command? (2 Replies)
Discussion started by: NycUnxer
2 Replies
Login or Register to Ask a Question