From owner-freebsd-questions@FreeBSD.ORG Mon Mar 22 19:20:35 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id AC09916A4CE for ; Mon, 22 Mar 2004 19:20:35 -0800 (PST) Received: from mercury.solis8.net (adsl-63-202-83-44.dsl.snfc21.pacbell.net [63.202.83.44]) by mx1.FreeBSD.org (Postfix) with ESMTP id 90E5B43D41 for ; Mon, 22 Mar 2004 19:20:35 -0800 (PST) (envelope-from addymin@pacbell.net) Received: from pacbell.net (mars.solis8.net [192.168.1.10]) by mercury.solis8.net (Postfix) with ESMTP id ED31920B1C1 for ; Mon, 22 Mar 2004 19:20:35 -0800 (PST) Message-ID: <405FADAD.3010107@pacbell.net> Date: Mon, 22 Mar 2004 19:23:25 -0800 From: Miguel User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.6) Gecko/20040113 X-Accept-Language: en-us, en MIME-Version: 1.0 To: freebsd-questions Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit Subject: Where is OpenSSH? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: addymin@pacbell.net List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 23 Mar 2004 03:20:35 -0000 Greetings: I have several RH-9 servers that I'd like to migrate to FreeBSD 4.9 latter this year. So I put up a test 4.9 server to get fully acquainted before heading off to a new universe [grin]. My Question: I read a CERT notification about the OpenSSH vulnerability (just a few days ago) so if needed, I'd like to apply an upgraded OpenSSH to the FreeBSD server. But when I went to the freebsd.org's errata page (http://www.freebsd.org/releases/4.9R/errata.html), I didn't see a reporting of the OpenSSH vulnerability. Is FreeBSD's OpenSSH not vulnerable then? (I guess not??) However... where is OpenSSH? After running cvsup and "make index && make readmes", I ran "pkg_version -v". The output showed that all of my installed programs were up to date with the ports (am I reading this right?). I ran "pkg_info" and there was no OpenSSH, only "OpenSSH-askpass". [BTW, here is my supfile] *default host=cvsup6.FreeBSD.org *default base=/usr *default prefix=/usr *default release=cvs tag=RELENG_4_9 *default delete use-rel-suffix On my Redhat boxes I just run "apt-get" and the patched OpenSSH packages are right there. I'm fairly new at FreeBSD so please forgive my stumblings about :) Thank you, Michael