Gentoo Security Advisory GLSA 200602-11 (OpenSSH)

Summary
The remote host is missing updates announced in advisory GLSA 200602-11.
Solution
All OpenSSH users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose '>=net-misc/openssh-4.2_p1-r1' All Dropbear users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose '>=net-misc/dropbear-0.47-r1' http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200602-11 http://bugs.gentoo.org/show_bug.cgi?id=119232
Insight
A flaw in OpenSSH and Dropbear allows local users to elevate their privileges via scp.