Bugtraq post on putty "proof of concept"

From: NOSPAM@sonic.net
Date: 12/30/02

  • Next message: Neil W Rickert: "Re: Bugtraq post on putty "proof of concept""
    From: <NOSPAM@sonic.net>
    Date: Mon, 30 Dec 2002 02:03:26 GMT
    
    

    Hello,

    I see:(Dec. 28, 2002)
    http://online.securityfocus.com/archive/1/304609/2002-12-27/2003-01-02/

    and: (Dec. 17, 2002)
    http://online.securityfocus.com/archive/1/303724

    and (Dec 16, 2002)
    http://online.securityfocus.com/archive/1/303537

    The latest putty (beta v0.53b) was released Dec. 12, 2002.

    Upon inspecting the Changes
    ( http://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html )
    I see general notes of security fixes in 0.53 and 0.53b, but nothing explicit.
    Do either, neither or both of these have fixes against the reported bug in
    ssh2 implementation?

    Often, exploits are created for older versions where present (newer) versions
    have fixes shortly after a new version comes out. In this case, *if* the
    present version(s) are imune to the proof of concept, then it is simple to
    understand that there is no way that the latest changes log could reference
    bugtraq items that it did not know about - even if the latest version is
    immune to it. :-)

    (As per the web page home, I am posting my question here instead of sending
    e-mail to the development team.)

    (To reply in email, remove the words "no" and "spam" and replace with
    "cotman")

    TIA,
    -ME



    Relevant Pages

    • Re: clients cannot access companyweb
      ... the fixes were not quite explicit enough for me ... Any chance someone can enlighten me? ... > Tnx;) ...
      (microsoft.public.windows.server.sbs)
    • Re: [stable] Linux 2.6.25.10
      ... why aren't security fixes that you fix relevant to users ... Backporting any fix to older kernels is a chore, ... make the life of people doing the actual backports (paid for, commercial, ...
      (Linux-Kernel)
    • Re: Pricing SuSE linux enterprise 10
      ... Security fixes available in real-time via YOU ... Security and/or major bug fixes applied via YOU ... If you are talking about paid-for support for bug reporting, ...
      (alt.os.linux.suse)
    • Re: Security Announcements
      ... >> branch will be that it simply carries security fixes, ... Will there be ctm/ftp snapshot tracking ... necessary to efficiently produce and maintain binary updates. ...
      (FreeBSD-Security)
    • Re: starting with 2.7
      ... >>the last 2.6 release every six months and backport security fixes to it ... > we're trying to keep a properly fixed 2.6.8 tree for Debian sarge. ... Several of us have suggested that only security fixes and fixes for bugs ...
      (Linux-Kernel)