Exploit in ssh?

2003-09-16 Thread moseley
I saw this:

http://lists.netsys.com/pipermail/full-disclosure/2003-September/010116.html

Anyone know more about it?

-- 
Bill Moseley
[EMAIL PROTECTED]


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED] 
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Re: Exploit in ssh?

2003-09-16 Thread Colin Watson
On Tue, Sep 16, 2003 at 08:25:59AM -0700, [EMAIL PROTECTED] wrote:
 I saw this:
 
 http://lists.netsys.com/pipermail/full-disclosure/2003-September/010116.html
 
 Anyone know more about it?

Fixed packages are being prepared. The update for stable has already
been released.

-- 
Colin Watson  [EMAIL PROTECTED]


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED] 
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Re: Exploit in ssh?

2003-09-16 Thread Thomas Krennwallner
Hi!

On Tue Sep 16, 2003 at 08:25:59AM -0700, [EMAIL PROTECTED] wrote:
 http://lists.netsys.com/pipermail/full-disclosure/2003-September/010116.html
 
 Anyone know more about it?

For woody there is an update available at security.debian.org

So long
Thomas

-- 
 .''`.  Obviously we do not want to leave zombies around. - W. R. Stevens
: :'  : Thomas Krennwallner djmaecki at ull dot at
`. `'`  1024D/67A1DA7B 9484 D99D 2E1E 4E02 5446  DAD9 FF58 4E59 67A1 DA7B
  `-http://bigfish.ull.at/~djmaecki/


pgp0.pgp
Description: PGP signature


Re: Exploit in ssh?

2003-09-16 Thread Michael D Schleif
Colin Watson [EMAIL PROTECTED] [2003:09:16:16:32:02+0100] scribed:
 On Tue, Sep 16, 2003 at 08:25:59AM -0700, [EMAIL PROTECTED] wrote:
  I saw this:
  
  http://lists.netsys.com/pipermail/full-disclosure/2003-September/010116.html
  
  Anyone know more about it?
 
 Fixed packages are being prepared. The update for stable has already
 been released.

Also:

openssh (1:3.6.1p2-6.0.fixed) unstable; urgency=low

  * Apply 
http://www.freebsd.org/cgi/cvsweb.cgi/src/crypto/openssh/buffer.c.diff?r1=1.1.1.6r2=1.1.1.7

 -- Ivo Timmermans [EMAIL PROTECTED]  Tue, 16 Sep 2003 13:11:45 +0200

-- 
Best Regards,

mds
mds resource
877.596.8237
-
Dare to fix things before they break . . .
-
Our capacity for understanding is inversely proportional to how much
we think we know.  The more I know, the more I know I don't know . . .
--


pgp0.pgp
Description: PGP signature


Re: Exploit in ssh?

2003-09-16 Thread Ed Curtis


On Tue, 16 Sep 2003, Thomas Krennwallner wrote:

 Hi!

 On Tue Sep 16, 2003 at 08:25:59AM -0700, [EMAIL PROTECTED] wrote:
  http://lists.netsys.com/pipermail/full-disclosure/2003-September/010116.html
 
  Anyone know more about it?

 For woody there is an update available at security.debian.org

 So long
 Thomas


 Yep there sure is and it seems everyone on the planet that runs debian is
now getting the update. Can't get to the site at all :)

Ed



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED] 
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]