Re: new unpublished SSH exploit ?

From: Patrick Lamb (pdlambat_at_comcast.net)
Date: 09/18/03


Date: Wed, 17 Sep 2003 21:49:43 -0500

On Wed, 17 Sep 2003 04:37:02 GMT, Nico Kadel-Garcia
<nkadel@verizon.net> wrote:

>David Magda wrote:
>
>> dtucker@dodgy.net.au (Darren Tucker) writes:
>>
>>
>>>OpenSSH 3.7 (and 3.7p1) were released a couple of hours ago. The
>>>announcement does not appear to have hit the list archives yet.
>>
>> [...]
>>
>> There is also a patch available if you do not want to upgrade to a
>> newer version (which can change other behaviour):
>>
>> http://www.openssh.com/txt/buffer.adv
>>
>
>It got slashdotted earlier today: RedHat has already published updated
>RPM's for their more recent OS releases, since the patch is quite small
>and intelligible.

FWIW, Redhat has updated the updated RPMs for openssh today (9/17).

Pat



Relevant Pages

  • Re: redhat patch problem?
    ... I've since successfully migrated all of my legacy redhat OS's ... As far as i know this method can not be used to upgrade to RHEL ... > you can use in lieu of fedoralegacy. ... I guess that fedoralegacy doesn't any patch any more after ...
    (Focus-Linux)
  • Re: new unpublished SSH exploit ?
    ... On Wed, 17 Sep 2003 04:37:02 GMT, Nico Kadel-Garcia ... >> There is also a patch available if you do not want to upgrade to a ... >RPM's for their more recent OS releases, since the patch is quite small ... Redhat has updated the updated RPMs for openssh today. ...
    (comp.security.ssh)
  • Re: To Anyone who has Internet Explorer Installed or any other browser (Everybody)
    ... >> patch the affected versions. ... This much is known about Microsoft: ... when they do, it is often as a part of a forced "upgrade", ... DRM scheme than to build in fundamental flaws, ...
    (alt.computer.security)
  • Re: Liveupgrade and ZFS: Not for workstations!
    ... I can't use live upgrade to ... Or you can create a new BE and patch that, ... If I'm adding patches that don't require single user mode or a reboot, I just take s snapshot of the pool and patch. ... second disk for one reason or another. ...
    (comp.unix.solaris)
  • Re: Patching Solaris 9 systems to "current"
    ... patch bundle onto them. ... and in some ways better approach is to do an upgrade ... time for a reboot, with another reboot to back out. ... additional disks to hand). ...
    (comp.unix.solaris)