Re: SSH question!??!

From: Tim Haynes (usenet@stirfried.vegetable.org.uk)
Date: 03/13/02


From: Tim Haynes <usenet@stirfried.vegetable.org.uk>
Date: Tue, 12 Mar 2002 23:14:51 +0000

Dragan Cvetkovic <d1r2a3g4a5n.NOSPAM@soli99ton.com> writes:

>> > Remember also that all OpenSSH versions use zlib, which has just been
>> > shown to have a problem.
>>
>> Does that mean we have to upgrade to 3.2?
>
> I though that zlib is dynamically linked to ssh (at least on my Debian
> system), so upgrading /usr/lib/libz.so.1 should be enough. Or am I wrong?

I had this thought as well; from what I saw on debian-secure as well,
dynamically linked against libz is fine, it's statically linked packages
that have problems.

I thought the OpenSSH vulnerability was a separate affair; see
<http://www.openbsd.org/advisories/ssh_channelalloc.txt> for more.

~Tim

-- 
Rushing onwards, tracing the chains,        |piglet@stirfried.vegetable.org.uk
Chasing the days, chasing the days.         |http://spodzone.org.uk/



Relevant Pages