From owner-freebsd-security Tue Jun 25 3:37: 3 2002 Delivered-To: freebsd-security@freebsd.org Received: from citi.umich.edu (citi.umich.edu [141.211.133.111]) by hub.freebsd.org (Postfix) with ESMTP id 4B15E37B407 for ; Tue, 25 Jun 2002 03:36:53 -0700 (PDT) Received: by citi.umich.edu (Postfix, from userid 104123) id 9F2E3207C1; Tue, 25 Jun 2002 06:36:48 -0400 (EDT) Date: Tue, 25 Jun 2002 06:36:48 -0400 From: Niels Provos To: Brian Nelson Cc: FreeBSD Security Subject: Re: ENOUGH!!! Re: [openssh-unix-announce] Re: Upcoming OpenSSH vulner ability (fwd) Message-ID: <20020625103648.GG15772@citi.citi.umich.edu> References: <20020625074744.GK53232@elvis.mu.org> <3D1825E7.4030201@notgod.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <3D1825E7.4030201@notgod.com> User-Agent: Mutt/1.3.27i Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org On Tue, Jun 25, 2002 at 01:12:23AM -0700, Brian Nelson wrote: > I think I personally don't disagree with Theo, but I am confused about > the state of Privelage Seperation for people not running > (Open|NET)BSD... So it's a hard pill to swallow when the software is "a > few days old". I am much more comfortable with a patched version coming Privilege Separation has been committed to OpenSSH in the middle of March this year. It is not just a few days old. To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message