Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 15 Nov 1999 15:16:10 -0800 (PST)
From:      Kris Kennaway <kris@hub.freebsd.org>
To:        John Hay <jhay@mikom.csir.co.za>
Cc:        Brian Fundakowski Feldman <green@FreeBSD.ORG>, freebsd-security@FreeBSD.ORG
Subject:   Re: ssh-1.2.27 remote buffer overflow - work around ??
Message-ID:  <Pine.BSF.4.10.9911151508160.79689-100000@hub.freebsd.org>
In-Reply-To: <199911150602.IAA13567@zibbi.mikom.csir.co.za>

next in thread | previous in thread | raw e-mail | index | archive | help
On Mon, 15 Nov 1999, John Hay wrote:

> > reason.  I can't condone this technically illegal action.  The better
> > question is why aren't you using OpenSSH?
> 
> Well, is there a way of not using rsh to fetch it? Our firewall don't
> allow incoming tcp connections and rsh needs one.

Ahh yes, remote cvs uses rsh :-(

Short of using the real SSH to fetch openSSH (which won't be useful if
you're trying to fetch openssh because you can't legally use SSH in your
situation in the first place) I can't think of another way to get it via
CVS.

Perhaps we'll have to fall back to tarring up the source on a non-US ftp
server..this is probably a problem for a lot of people :-(

Kris

----
Cthulhu for President! For when you're tired of choosing the _lesser_ of
two evils..



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.10.9911151508160.79689-100000>