GnuGk Security Alert: libssh vulnerability

Jan Willamowius <[email protected]> Wed, 17 Oct 2018 16:55:14 +0200
Newsgroups gmane.comp.telephony.openh323gk.user
Message-ID <[email protected]>
WARNING: You receive this message on the old GnuGk mailinglist that will go=
 away soon. Please re-subscribe for the new mailinglist at
https://lists.gnugk.org/cgi-bin/mailman/listinfo/gnugk-users

Hi,

a vulnerability in libssh 0.6 and above has been found that allows
access without credentials. GnuGk uses libssh if you enable SSH
encryption for the status port.

If you don't have SshStatusPort=3D1 in your configuration, then you are
_not_ affected by this issue.

Fix:
=3D=3D=3D=3D
Re-compile GnuGk with libssh 0.8.4 and 0.7.6.


Workaround:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Disable SSH on the status port:

[Gatekeeper::Main]
SshStatusPort=3D0


-- =

Jan Willamowius, Founder of the GNU Gatekeeper Project
EMail  : [email protected]
Website: https://www.gnugk.org
Support: https://www.willamowius.com/gnugk-support.html

Relaxed Communications GmbH
Frahmredder 91, 22393 Hamburg, Germany
Gesch=E4ftsf=FChrer: Jan Willamowius
HRB 125261 (Amtsgericht Hamburg)
USt-IdNr: DE286003584


_______________________________________________________

Posting: mailto:[email protected]
Archive: https://sourceforge.net/mailarchive/forum.php?forum_name=3Dopenh32=
3gk-users
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/openh323gk-users
Homepage: https://www.gnugk.org/