Re: FreeBSD Security Advisory FreeBSD-SA-15:22.openssh

2015-08-27 Thread Borja Marcos
On Aug 27, 2015, at 3:08 PM, Mike Tancsa wrote: On 8/27/2015 3:24 AM, Dag-Erling Smørgrav wrote: For the latter two, I am trying to understand in the context of a shared hosting system. Could one user with sftp access to their own directory use these bugs to gain access to another user's

Re: FreeBSD Security Advisory FreeBSD-SA-15:22.openssh

2015-08-27 Thread Dag-Erling Smørgrav
Mike Tancsa m...@sentex.net writes: For the latter two, I am trying to understand in the context of a shared hosting system. Could one user with sftp access to their own directory use these bugs to gain access to another user's account ? Once again: both of these are attacks on the main sshd

Re: FreeBSD Security Advisory FreeBSD-SA-15:22.openssh

2015-08-27 Thread Peter Pentchev
On Thu, Aug 27, 2015 at 03:19:04PM +0200, Borja Marcos wrote: On Aug 27, 2015, at 3:08 PM, Mike Tancsa wrote: On 8/27/2015 3:24 AM, Dag-Erling Smørgrav wrote: For the latter two, I am trying to understand in the context of a shared hosting system. Could one user with sftp access to

Re: FreeBSD Security Advisory FreeBSD-SA-15:22.openssh

2015-08-27 Thread Dag-Erling Smørgrav
Mike Tancsa m...@sentex.net writes: I know RELENG_8 is no longer supported, but does this issue impact FreeBSD 8.x ? Note that of the three issues mentioned here, one is not exploitable by an attacker and the other two presuppose a compromised pre-auth child. DES -- Dag-Erling Smørgrav -

Re: FreeBSD Security Advisory FreeBSD-SA-15:22.openssh

2015-08-26 Thread Bryan Drewery
On 8/26/2015 12:07 PM, Mike Tancsa wrote: On 8/25/2015 5:27 PM, FreeBSD Security Advisories wrote: = FreeBSD-SA-15:22.opensshSecurity Advisory Topic: OpenSSH multiple