From owner-freebsd-security Thu Aug 1 16:39:15 2002 Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.FreeBSD.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 3692737B400 for ; Thu, 1 Aug 2002 16:39:13 -0700 (PDT) Received: from jive.SoftHome.net (jive.SoftHome.net [66.54.152.27]) by mx1.FreeBSD.org (Postfix) with SMTP id A4F3743E6A for ; Thu, 1 Aug 2002 16:39:11 -0700 (PDT) (envelope-from yid@softhome.net) Received: (qmail 30974 invoked by uid 417); 1 Aug 2002 23:39:11 -0000 Received: from shunt-smtp-out-0 (HELO softhome.net) (172.16.3.12) by shunt-smtp-out-0 with SMTP; 1 Aug 2002 23:39:11 -0000 Received: from unknown ([216.194.6.221]) (AUTH: LOGIN yid@softhome.net) by softhome.net with esmtp; Thu, 01 Aug 2002 17:39:09 -0600 Date: Thu, 1 Aug 2002 19:37:39 -0400 From: Joshua Lee To: Artur Lindgren Cc: freebsd-security@FreeBSD.ORG Subject: Re: Trojan located in latest openssh tar files Message-Id: <20020801193739.3b40bcb8.yid@softhome.net> In-Reply-To: References: Organization: Plan B Software Labs X-Mailer: Sylpheed version 0.8.0claws (GTK+ 1.2.10; i386-portbld-freebsd4.6) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org On Thu, 1 Aug 2002 14:11:24 +0200 Artur Lindgren wrote: > I noticed that openssh-3.4p has a trojan horse (available from > >ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-3.4p1.tar.gz > and some of the mirrors. Is this a problem for someone who makes world with FreeBSD and gets OpenSSH from the source tree or only for people who get OpenSSH via ports? To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message