Jump to content

Welcome Guest! To access all forums & features, please register an account or sign-in. → Why register?




Photo

Upgrade openssh 4.5 on openBSD 4.0 ?


  • Please log in to reply
5 replies to this topic - - - - -

#1 zoheb

zoheb

    Neowinian²

  • 243 posts
  • Location: haLLuNicaTeD pAradISe

Posted 06 July 2012 - 21:44

Hii,

I am new to openbsd. Can someone tell me how to upgrade openssh 4.5 to openssh 5.7 +

Current ssh (4.5) is vulnerable to :
openssh-server Forced Command Handling Information Disclosure Vulnerability

Can you please provide me with some solution to upgrade ssh on openBSD 4.0?

There are nice steps involved here but with these steps, I need to update my ssh linearly like from 4.5 to 4.6 to 4.8 and then apply the patch and then 4.9 till 6.0 version.

http://www.openssh.org/openbsd.html

Last question would be, the above link states the steps to install patch while updating openssh on OpenBSD 4.3, 4.2 or 4.1, Do I need the apply this patch on openBSD 4.0 too ?


#2 +BudMan

BudMan

    Neowinian Super Star

  • 23,898 posts
  • Location: Schaumburg, IL
  • OS: Win7, Vista, 2k3, 2k8, XP, Linux, FreeBSD, OSX, etc. etc.

Posted 07 July 2012 - 13:49

4.0? Really - that's from what late 2006? So like 7 year old release, why not just update to the current 5.1?

#3 OP zoheb

zoheb

    Neowinian²

  • 243 posts
  • Location: haLLuNicaTeD pAradISe

Posted 07 July 2012 - 16:41

Currently our Firewall is deployed on openBSD 4.0. Can't take risks for upgrading the server. Just needs to upgrade openSSH to resolve the vulnerability.

Thanks

#4 ChuckFinley

ChuckFinley

    Neowinian DOMINATING

  • 8,677 posts

Posted 07 July 2012 - 16:44

Thats the only thing your worried about? lol I would have thought it would be a case of yum install openssh I think...

#5 +BudMan

BudMan

    Neowinian Super Star

  • 23,898 posts
  • Location: Schaumburg, IL
  • OS: Win7, Vista, 2k3, 2k8, XP, Linux, FreeBSD, OSX, etc. etc.

Posted 07 July 2012 - 19:21

So your 7 year firewall OS and the only exploit your worried about is running 7 year old version of ssh.

From looking at your patch link, you sure current will even run on that old of OS? They show patches for 4.1 starting on 4.9, then then again for 5.2 on like 4.4 and 4.3.

Not clear how to read that if you wanted to run say 5.2 on 4.2 or 4.1, etc.. So why are patches needed for only specific older versions, but versions before that work fine? Thats not how I would read it, I would read it as min required to run that version is X, etc.

Wonder if I could even find 4.0 to download and install?

#6 Miuku.

Miuku.

    A damned noob

  • 4,885 posts
  • Location: Finland, EU
  • OS: :: OS X :: SLES ::

Posted 07 July 2012 - 19:31

http://ftp.nluug.nl/pub/OpenBSD/

They have like every OpenBSD for the last 11 years :p