Date: Tue, 16 Sep 2003 10:00:56 -0500 From: D J Hawkey Jr <hawkeyd@visi.com> To: freebsd-security@freebsd.org Subject: Re: OpenSSH heads-up Message-ID: <20030916150056.GA16806@sheol.localdomain> In-Reply-To: <20030916145525.GB90755@madman.celabo.org> References: <20030916134347.GA30359@madman.celabo.org> <Pine.LNX.4.58.0309161046030.11275@ori.ccmr.cornell.edu> <20030916145525.GB90755@madman.celabo.org>
next in thread | previous in thread | raw e-mail | index | archive | help
On Sep 16, at 09:55 AM, Jacques A. Vidrine wrote: > > Here's the meat of it: > > ---- begin excerpt ---- > This is the 1st revision of the Advisory. > > This document can be found at: http://www.openssh.com/txt/buffer.adv > > 1. Versions affected: > > All versions of OpenSSH's sshd prior to 3.7 contain a buffer > management error. It is uncertain whether this error is > potentially exploitable, however, we prefer to see bugs > fixed proactively. > > 2. Solution: > > Upgrade to OpenSSH 3.7 or apply the following patch. > ---- end excerpt ---- How far away are we from a FreeBSD SA? When the patch(es) are ready for all the other supported releases? Dave -- ______________________ ______________________ \__________________ \ D. J. HAWKEY JR. / __________________/ \________________/\ hawkeyd@visi.com /\________________/ http://www.visi.com/~hawkeyd/
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20030916150056.GA16806>