MDKSA-2005:172 : openssh
Medium Nessus Plugin ID 20426
SynopsisThe remote Mandrake host is missing one or more security-related patches.
DescriptionSshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts.
GSSAPI is only enabled in versions of openssh shipped in LE2005 and greater.
The updated packages have been patched to correct this issue.
SolutionUpdate the affected package(s).