Re: FreeBSD Security Advisory FreeBSD-SA-01:24.ssh

From: The Hermit Hacker (scrappy@hub.org)
Date: 02/14/01


Date: Wed, 14 Feb 2001 15:50:02 -0400 (AST)
From: The Hermit Hacker <scrappy@hub.org>
To: Nate Williams <nate@yogotech.com>

On Wed, 14 Feb 2001, Nate Williams wrote:

> > > > OpenSSH is installed if you chose to install the 'crypto' distribution
> > > > at install-time or when compiling from source, and is installed and
> > > > enabled by default as of FreeBSD 4.1.1-RELEASE. By default SSH1
> > > > protocol support is enabled.
> > >
> > > Excuse me pointing to a similar point in the last few advisories,
> > > but , again, for some reason earlier releases 4.0 and 4.1 are forgotten.
> > > While the advisory includes those releases in the list
> > > of vulnerable systems, the paragraph quoted above tells that
> > > OpenSSH is install as of FreeBSD 4.1.1-RELEASE.
> > > However, I see that 4.0-RELEASE had OpenSSH-1.2.2
> > > and it is, according to the quote below is vulnerable.
> >
> > If you look at http://www.freebsd.org/security we only claim to
> > provide security support for the most recent version of FreeBSD
> > (4.2-RELEASE) and after.
>
> I agree that 'support' is one thing, but at least mentioning which
> releases are effected by this bug would be good.
>
> Most of the other vendors list all of their 'effected' releases as being
> effected or not, and since most of the deployed FreeBSD systems are
> *NOT* running 4.2R, this is of great benefit to the users.

If nothing else, by listed anything before 4.2R as *being* vulnerable, but
unsupported, you give ppl one more incentive to dive into upgrading ...

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: FreeBSD Patch question
    ... >My intention is to apply the patches as instructed in the advisories. ... I'll resolve my issues with pgp so that I can validate the files first, then apply them one at a time. ... advise people running production servers to run the -STABLE branch. ... The most stable FreeBSD ...
    (FreeBSD-Security)
  • [FreeBSD-Announce] FreeBSD Errata Notice FreeBSD-EN-08:01.libpthread
    ... For general information regarding FreeBSD Errata Notices and Security ... Advisories, including descriptions of the fields above, security ... The following patch has been verified to apply to FreeBSD 6.3 systems: ...
    (freebsd-announce)
  • [FreeBSD-Announce] FreeBSD Errata Notice FreeBSD-EN-09:04.fork
    ... For general information regarding FreeBSD Errata Notices and Security ... Advisories, including descriptions of the fields above, security ... # fetch http://security.FreeBSD.org/patches/EN-09:04/fork.patch.asc ...
    (freebsd-announce)
  • Re: Security Announcements?
    ... > than silence from the security officer. ... when the fix is available. ... FreeBSD has done updated advisories in the past, ...
    (FreeBSD-Security)