[TriLUG] Enjoy upgrading all your SSH boxen to 3.7?

Kevin Sonney alchemist at darkcanvas.com
Wed Sep 17 21:23:37 EDT 2003


Brian Daniels <bitmage at bellsouth.net> writes:
>   All versions of OpenSSH's sshd prior to 3.7.1 contain buffer
>   management errors.  It is uncertain whether these errors are
>   potentially exploitable, however, we prefer to see bugs
>   fixed proactively.

As a reminder, Red Hat's RPM packages are back ports of the fix to the
version of ssh that shipped with Red Hat Linux and Red Hat Enterprise
Linux (as applicable). Remind your clients/friends of that when they
complain about Red Hat (and other vendors) not shipping the "current"
package versions.

Just a little FYI *grin*

--- 
----------------------------------
--         Kevin Sonney         --
--  ICQ: 4855069  AIM: ksonney  --
----------------------------------
320C 0336 3BC4 13EC 4AEC  6AF2 525F CED7 7BB6 12C9
 Nobody can be exactly like me. Sometimes even I have trouble doing it.
 -- Tallulah Bankhead
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 188 bytes
Desc: not available
URL: <http://www.trilug.org/pipermail/trilug/attachments/20030917/050acf3c/attachment.pgp>


More information about the TriLUG mailing list