Description: Globus has acknowledged two vulnerabilities in GSI-OpenSSH, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a vulnerable system.
The vulnerabilities are reported in the following products and versions:
* Globus Toolkit versions 4.0.0-4.0.3 and 4.1.0-4.1.1
* GSI-OpenSSH version 3.8 and prior
NOTE: Globus Toolkit 4.0.4 reportedly includes GSI-OpenSSH 3.9, which is not affected. Globus Toolkit 3.2 and prior reportedly do not include GSI-OpenSSH.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.