Debian GNU/Linux Advisory: ssh-krb5

Sep 17, 2003, 20:06 (0 Talkback[s])

Debian Security Advisory DSA-383-1 Wichert Akkerman
September 17, 2003  

Package : ssh-krb5
Vulnerability : buffer handling
Problem type : possible remote
Debian-specific : no
CVS references : CAN-2003-0693 CAN-2003-0695

Several bugs have been found in OpenSSH's buffer handling. It is not known if these bugs are exploitable, but as a precaution an upgrade is advised.

For the Debian stable distribution these bugs have been fixed in version 1:3.4p1-0woody3 .

Upgrade Instructions

wget url

will fetch the file for you
dpkg -i file.deb

will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

apt-get update

will update the internal database apt-get upgrade

will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody

Debian Security team <>