BSD Help
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsOperating SystemsBSD Help

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Stay one step ahead of the competition. Evaluate and give feedback on some of the hottest web development tools on the market today. Make your opinion heard! Click Here
  #1  
Old September 17th, 2003, 08:16 PM
mystik_web's Avatar
mystik_web mystik_web is offline
No one Important
Dev Shed Novice (500 - 999 posts)
 
Join Date: Aug 2000
Location: Australia
Posts: 524 mystik_web User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 12 h 38 m 24 sec
Reputation Power: 8
Send a message via ICQ to mystik_web
OpenSSH buffer management error - Upgrade help

Hello there I was wondering if someone could point me into the correct direction.

I would like to update my system in responce to the Advisory on the Opens SSH buffer management error. and would liek to know which option to use in the upgrade.

I am currently running:-

FreeBSD my.host.com 4.7-RELEASE FreeBSD 4.7-RELEASE #0: Tue Jun 3 15:31:21 CST 2003 root@my.host.com:/usr/src/sys/compile/NEWSERVE
R i386

Open ssh is:-
Server
sshd version OpenSSH_3.4p1 FreeBSD-20020702

Client
OpenSSH_3.4p1 FreeBSD-20020702, SSH protocols 1.5/2.0, OpenSSL 0x0090607f

Open SSH was installed as the base install at time of system installation.

If I can help it I do not want to upgrade the whole system as it is running as a web server, and other applications are running on it, all I would prefer to be able to do is to apply the patch.

is it safe to just apply the patch in this case? as shown in the following choices from the advisory email:-

1) Upgrade your vulnerable system to 4-STABLE or to the RELENG_5_1,
RELENG_4_8, or RELENG_4_7 security branch dated after
the correction date (5.1-RELEASE-p3, 4.8-RELEASE-p5, or
4.7-RELEASE-p15, respectively).

2) FreeBSD systems prior to the correction date:

The following patches have been verified to apply to FreeBSD 4.x and
FreeBSD 5.x systems prior to the correction date.

Download the appropriate patch and detached PGP signature from the following
locations, and verify the signature using your PGP utility.

[FreeBSD 4.3 and 4.4]
# fetch ftp://ftp.FreeBSD.org/pub/FreeBSD/C.../buffer44.patch
# fetch
ftp://ftp.FreeBSD.org/pub/FreeBSD/C...fer44.patch.asc

[FreeBSD 4.5]
# fetch ftp://ftp.FreeBSD.org/pub/FreeBSD/C.../buffer45.patch
# fetch
ftp://ftp.FreeBSD.org/pub/FreeBSD/C...fer45.patch.asc

[FreeBSD 4.6 and later, FreeBSD 5.0 and later]
# fetch ftp://ftp.FreeBSD.org/pub/FreeBSD/C.../buffer46.patch
# fetch
ftp://ftp.FreeBSD.org/pub/FreeBSD/C...fer46.patch.asc

Execute the following commands as root:

# cd /usr/src
# patch < /path/to/sshd.patch
# cd /usr/src/secure/lib/libssh
# make depend && make all install
# cd /usr/src/secure/usr.sbin/sshd
# make depend && make all install
# cd /usr/src/secure/usr.bin/ssh
# make depend && make all install

Be sure to restart `sshd' after updating.

# kill `cat /var/run/sshd.pid`
# /usr/sbin/sshd

If someone could shed a little bit of light on this for me it would be greatly appreciated.

Reply With Quote
  #2  
Old September 18th, 2003, 04:35 PM
Prime Mover Prime Mover is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2003
Location: Jersey
Posts: 64 Prime Mover User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 5
Well, I usually make world to upgrade my systems, which you indicated you didn't want to do, and I can understand... the first couple times I did it it was a little unnerving to say the least, but once I got the hang of it, it was apiece of cake.

As for you, the patch instructions they give are pretty decent, and following them should get you the results you're looking for without needing to rebuild the whole system.

Just make sure the patch applies cleanly - it will give you good output telling you if it failed. As long as the patch applies cleanly, do the makes, and you'll be all set. If any SSH connections are open before/during the update, you'll probably have to restart the sshd deamon, or at least reconnect your sessions, but you should be OK.

-Gary
__________________
Trying to change its program
Trying to change the mode...crack the code
Images conflicting into data overload

Reply With Quote
Reply

Viewing: Dev Shed ForumsOperating SystemsBSD Help > OpenSSH buffer management error - Upgrade help


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 6 hosted by Hostway