Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 16 Sep 2003 10:00:56 -0500
From:      D J Hawkey Jr <hawkeyd@visi.com>
To:        freebsd-security@freebsd.org
Subject:   Re: OpenSSH heads-up
Message-ID:  <20030916150056.GA16806@sheol.localdomain>
In-Reply-To: <20030916145525.GB90755@madman.celabo.org>
References:  <20030916134347.GA30359@madman.celabo.org> <Pine.LNX.4.58.0309161046030.11275@ori.ccmr.cornell.edu> <20030916145525.GB90755@madman.celabo.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On Sep 16, at 09:55 AM, Jacques A. Vidrine wrote:
> 
> Here's the meat of it:
> 
> ---- begin excerpt ----
>  This is the 1st revision of the Advisory.
> 
>  This document can be found at:  http://www.openssh.com/txt/buffer.adv
> 
>  1. Versions affected:
> 
>         All versions of OpenSSH's sshd prior to 3.7 contain a buffer
>         management error.  It is uncertain whether this error is
>         potentially exploitable, however, we prefer to see bugs
>         fixed proactively.
> 
>  2. Solution:
> 
>         Upgrade to OpenSSH 3.7 or apply the following patch.
> ---- end excerpt ----

How far away are we from a FreeBSD SA? When the patch(es) are ready
for all the other supported releases?

Dave

-- 
  ______________________                         ______________________
  \__________________   \    D. J. HAWKEY JR.   /   __________________/
     \________________/\     hawkeyd@visi.com    /\________________/
                      http://www.visi.com/~hawkeyd/



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20030916150056.GA16806>