Title : Ubuntu Security Update Fixes OpenSSH Multiple Vulnerabilities VUPEN ID : VUPEN/ADV-2008-2728 CVE ID : CVE-2008-1657 - CVE-2008-4109
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-10-06
Technical Description
Two vulnerabilities have been identified in Ubuntu, which could be exploited by malicious users to execute arbitrary code or by remote attackers to cause a denial of service. These issues are caused by errors in OpenSSH. For additional information, see : VUPEN/ADV-2008-1035 - VUPEN/ADV-2008-2592
Ubuntu 6.06 LTS - Upgrade to openssh-server version 1:4.2p1-7ubuntu3.5
Ubuntu 7.04 - Upgrade to openssh-server version 1:4.3p2-8ubuntu1.5
Ubuntu 7.10 - Upgrade to openssh-server version 1:4.6p1-5ubuntu0.6 References