From owner-freebsd-security Wed Jun 26 7:37:28 2002 Delivered-To: freebsd-security@freebsd.org Received: from obsidian.sentex.ca (obsidian.sentex.ca [64.7.128.101]) by hub.freebsd.org (Postfix) with ESMTP id 4AB7A37B406 for ; Wed, 26 Jun 2002 07:37:16 -0700 (PDT) Received: from simian.sentex.net (pyroxene.sentex.ca [199.212.134.18]) by obsidian.sentex.ca (8.12.4/8.12.4) with ESMTP id g5QEbExd004188 for ; Wed, 26 Jun 2002 10:37:14 -0400 (EDT) (envelope-from mike@sentex.net) Message-Id: <5.1.0.14.0.20020626103651.048ec778@marble.sentex.ca> X-Sender: mdtpop@marble.sentex.ca X-Mailer: QUALCOMM Windows Eudora Version 5.1 Date: Wed, 26 Jun 2002 10:40:05 -0400 To: freebsd-security@FreeBSD.ORG From: Mike Tancsa Subject: OpenSSH Advisory (was Re: Much ado about nothing.) In-Reply-To: <20020626072326.A4270@mail.seattleFenix.net> References: <200206250248.g5P2mJLJ031907@cvs.openbsd.org> <20020625024401.GB43738@madman.nectar.cc> <200206250248.g5P2mJLJ031907@cvs.openbsd.org> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii"; format=flowed X-Virus-Scanned: By Sentex Communications (obsidian/20020220) Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org Can someone confirm for me that the quote, ---------- Impact: OpenBSD, FreeBSD-Current, and other OpenSSH implementations may be vulnerable to a remote, superuser compromise. Affected Versions: OpenBSD 3.0 OpenBSD 3.1 FreeBSD-Current OpenSSH 3.0-3.2.3 ------------end quote------------- would imply that the version 2.9 in STABLE is not vulnerable ? At 07:23 AM 26/06/2002 -0700, Benjamin Krueger wrote: >http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20584 > >Regards, > >-- >Benjamin Krueger > >"Life is far too important a thing ever to talk seriously about." >- Oscar Wilde (1854 - 1900) >---------------------------------------------------------------- >Send mail w/ subject 'send public key' or query for (0x251A4B18) >Fingerprint = A642 F299 C1C1 C828 F186 A851 CFF0 7711 251A 4B18 > >To Unsubscribe: send mail to majordomo@FreeBSD.org >with "unsubscribe freebsd-security" in the body of the message To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message