l i n u x - u s e r s - g r o u p - o f - d a v i s
Next Meeting:
July 7: Social gathering
Next Installfest:
Latest News:
Jun. 14: June LUGOD meeting cancelled
Page last updated:
2003 Sep 16 11:35

The following is an archive of a post made to our 'vox mailing list' by one of its subscribers.

Report this post as spam:

(Enter your email address)
[vox] The OpenSSH "exploit" is still being discussed...
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[vox] The OpenSSH "exploit" is still being discussed...

Just an FYI, there has been discussion on /. (slashdot) about a "new
openssh exploit in the wild"

Some people have posted statements about a worm.

Though a new version of openssh (3.7.1p1) is out, and I think Debian
(stable) , and RedHat both now have new packages out to provide fix for
the buffer allocation issue that some think are being exploited, there is
dissention among people about this patched code actually being the hole
that is alegedly being exploited.

So there is a hole, and it is exploitable or it isn't.
And there is either a worm exploiting this hole or there isn't.

Either way, you may wish to consider upgrading as a form of insurance, but
consider that if there is a hole being exploited, it is possible that this
fix is not the fix for the exploit in the wild (assuming it exists.)

Clear as mud?


vox mailing list

LUGOD Group on LinkedIn
Sign up for LUGOD event announcements
Your email address:
LUGOD Group on Facebook
'Like' LUGOD on Facebook:

Hosting provided by:
Sunset Systems
Sunset Systems offers preconfigured Linux systems, remote system administration and custom software development.

LUGOD: Linux Users' Group of Davis
PO Box 2082, Davis, CA 95617
Contact Us

LUGOD is a 501(c)7 non-profit organization
based in Davis, California
and serving the Sacramento area.
"Linux" is a trademark of Linus Torvalds.

Sponsored in part by:
O'Reilly and Associates
For numerous book donations.