From owner-freebsd-security Tue Jun 25 13: 1:34 2002 Delivered-To: freebsd-security@freebsd.org Received: from mail.interchange.ca (ns.interchange.ca [216.126.79.2]) by hub.freebsd.org (Postfix) with ESMTP id B3C3737B481 for ; Tue, 25 Jun 2002 13:00:28 -0700 (PDT) Received: by mail.interchange.ca (Fastmailer, from userid 555) id 54EB23C17; Tue, 25 Jun 2002 15:50:29 -0400 (EDT) MIME-Version: 1.0 Message-Id: <3D18C985.000067.31912@ns.interchange.ca> Content-Type: Multipart/Mixed; boundary="------------Boundary-00=_5S1AY293LIFNTT4D7TH0" To: rsidd@online.fr Subject: Re: Upcoming OpenSSH vulnerability Cc: security@FreeBSD.ORG From: "Michael Richards" X-Fastmail-IP: [24.43.130.241] Received: from 24.43.130.241 by www.fastmail.ca with HTTP; Tue, 25 Jun 2002 19:50:29 +0000 (UTC) Date: Tue, 25 Jun 2002 15:50:29 -0400 (EDT) Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org --------------Boundary-00=_5S1AY293LIFNTT4D7TH0 Content-Type: Text/Plain Content-Transfer-Encoding: 7bit >> Michael, Doug, any word on the status of this? Have the OpenSSH >> developers been notified of this? > > Reading the rest of that mail, I get the impression it was some > sort of dumb joke/rhetorical statement, he didn't really have an > exploit... Yes, I thought it was sarcastic enough that everyone would take it as that. As a result of something I saw this AM I believe it would be a great idea to upgrade immediately. There is an exploit out in the wild and it's been demonstrated to me. I've been spending all day frantically upgrading all of our machines. Will probably be up long into the night ensuring everything is up and working. -Michael _________________________________________________________________ http://fastmail.ca/ - Fast Secure Web Email for Canadians --------------Boundary-00=_5S1AY293LIFNTT4D7TH0-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message