[TriLUG] Fwd: Upcoming OpenSSH vulnerability *unverified*

Lisa Lorenzin lorenzin at 1000plus.com
Tue Jun 25 12:35:13 EDT 2002


new rpms don't appear to have made it onto rufus yet, but they're 
available at 

ftp://openbsd.secsup.org/pub/openbsd/OpenSSH/portable/rpm/RH73/

(7.3 RPM works on 7.2 - i'm not sure about older versions.)

looks to me like you have to upgrade to openssh 3.3p AND enable privilege
separation in sshd_config to mitigate.

                                                lisa


-- 
lisa lorenzin  |  lorenzin at 1000plus.com  |  http://www.1000plus.com/lisa/
of what avail is an open eye if the heart is blind? - solomon ibn gavirol




More information about the TriLUG mailing list