Re: SSH1 vulnerability ?

2001-02-14 Thread Frank Cusack
I'm able to verify that Foundry BigIron and NetIron 07.1.14T53 router code will reload due to this vulnerability (crc32 problem). All other versions of their code are probably vulnerable, and their other devices (eg ServerIron) are probably vulnerable also. ~f

Re: SSH1 vulnerability ?

2001-02-12 Thread Peter van Dijk
On Sat, Feb 10, 2001 at 03:08:11PM +0200, Tatu Ylonen wrote: > On Fri, 9 Feb 2001, Christophe Dupre wrote (on the [EMAIL PROTECTED] list): > > I just read Razor's vulnerability advisory, as reported on slashdot. > > Any truth to it, or is it another wannabe ? > > I suppose you are referring to thi

Re: SSH1 vulnerability ?

2001-02-12 Thread Markus Friedl
Tatu Ylonen wrote: > > > It's real enough for most vendors to respond. I think you want > > > to make sure your servers have at least 1.2.30/2.4.0 or > > > openssh 2.3.0p1 at this point. > > > > well, 1.2.30 does not contain a fix for this problem. > > No, but the current version is ssh-2.4.0, wh

Re: SSH1 vulnerability ?

2001-02-10 Thread Tatu Ylonen
On Fri, 9 Feb 2001, Christophe Dupre wrote (on the [EMAIL PROTECTED] list): > I just read Razor's vulnerability advisory, as reported on slashdot. > Any truth to it, or is it another wannabe ? I suppose you are referring to this one: > "Bindview released an advisory yesterday warning us that "[a]