Forum Discussion
GHUG_105220
Nimbostratus
Feb 04, 2011OpenSSH Version upgrade on BIGIP LTM
We had an external auditors come in and they alarmed us about a OpenSSH X11 Forward Session Hijacking vulerability that was present on our production LTM's. This issue is documented here: http://www.nessus.org/plugins/index...e&id=31737 What I did was upgrade to the latest BIGIP software version 10.2.1.297 and it still has an older version of OpenSSH: version OpenSSH_4.3p2 which still looks to be vulnerable to this exploit. Is there a way to just upgrade OpenSSH independantly so we can install the OpenSSH v5.0 or above to resolve this?
Thanks,
Greg
1 Reply
- hoolio
Cirrostratus
Hi,
Upgrading the packages on LTM is only supported as part of an OS upgrade. F5 generally issues updates for security fixes affecting the platform fairly quickly. In this case, it was determined that LTM is not vulnerable to this exploit. X11 forwarding isn't enabled by default in F5's sshd_config.
SOL9107: OpenSSH vulnerability CVE-2008-1483
http://support.f5.com/kb/en-us/solutions/public/9000/100/sol9107.html
Aaron
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects