Re: FreeBSD Security Notice FreeBSD-SN-02:03

From: Pete Fritchman (petef@absolutbsd.org)
Date: 05/28/02


Date: Tue, 28 May 2002 17:28:57 -0400
From: Pete Fritchman <petef@absolutbsd.org>
To: security@FreeBSD.org, security-officer@FreeBSD.org


++ 28/05/02 10:58 -0700 - FreeBSD Security Advisories:
| +------------------------------------------------------------------------+
| Port name: ssh2
| Affected: all versions
| Status: Not fixed
| Password authentication may be used even if password authentication
| is disabled.
| <URL:http://www.ssh.com/products/ssh/advisories/authentication.cfm>
| +------------------------------------------------------------------------+

FYI, I've just committed an update to the ssh2 port (now at version
3.1.2) which fixes this problem. Thanks to the port maintainer,
larse@ISI.EDU, for his quick response.

--pete

--
Pete Fritchman [petef@(databits.net|freebsd.org|csh.rit.edu)]
finger petef@databits.net for PGP key
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Cant send mail using Mail.app, but can with Thunderbird
    ... I can send mail out with password authentication. ... I can send it via port 25 normally or via port 465 via SSL. ... I've set mail to use port 25 without SSL. ...
    (comp.sys.mac.system)
  • Re: OT: Security....
    ... Don't use port 22. ... Disable password authentication and use RSA, ... If you only need SSH access from specific locations, ...
    (Fedora)
  • Re: FreeBSD Security Notice FreeBSD-SN-02:03
    ... Subject: FreeBSD Security Notice FreeBSD-SN-02:03 ... > | Password authentication may be used even if password authentication ... I've just committed an update to the ssh2 port (now at version ...
    (FreeBSD-Security)
  • Re: security question
    ... port 22 to the appropriate port, ... > logins on the local subnet with password authentication while at the same ... > time restricting external logins to public-key authentication on a single ... Check out the new MSN Search! ...
    (SSH)
  • Re: How to Stop Bruit Force ssh Attempts?
    ... The best thing you can do is move SSH to another port and disable ... password authentication, and use keys instead. ...
    (freebsd-questions)