-------- Original Message --------
> Great, thanks a lot!
Usually, audits allow for notifying as a false positive as scanning tools often
have false positives or technical vulnerabilities that aren't exploitable.
It sounds like these are all false positives unless your servers ssh client is
connecting to some oddly managed server.
--
All the best,
Kevin Chadwick
- Bogus CVE:s on OpenSSH? Raimo Niskanen
- Re: Bogus CVE:s on OpenSSH? Crystal Kolipe
- Re: Bogus CVE:s on OpenSSH? Stuart Henderson
- Re: Bogus CVE:s on OpenSSH? Florian Obser
- Re: Bogus CVE:s on OpenSSH? Raimo Niskanen
- Re: Bogus CVE:s on OpenSSH? Stuart Henderson
- Re: Bogus CVE:s on OpenSSH? Raimo Niskanen
- Re: Bogus CVE:s on OpenSSH? Kevin Chadwick
- Re: Bogus CVE:s on OpenSSH? Kevin Chadwick
- Re: Bogus CVE:s on OpenSSH? Raimo Niskanen

