Does anybody know if the openSSH exploit is applicable to Mac OS X?
and if so how does one apply the information shown here?

http://www.openssh.com/txt/buffer.adv


<http://docs.info.apple.com/article.html?artnum=106274>
states openSSH is used in OS X

http://docs.info.apple.com/article.html?artnum=61798
indicates an openSSH exploit patch that came out a year ago

need to know as I have two network admins giving me heat about slow patch releases... actually as I don't enable file/web/terminal etc sharing and turn on the firewall software when setting up users computers the issue is possibly not quite so urgent as they are making it out to be.

You could either wait for the Apple software update, or attempt to install OpenSSH 3.7.1 yourself (although I note that someone's just reported even more vulnerabilities that may need to be patched).

Note that:
* If you haven't enabled remote login, it's not a problem, and by default Mac OS X doesn't have this enabled (but I believe Mac OS X server does) * Exploits that work on Intel processors don't necessarily work on PowerPC based machines as the buffer has to be overrun with different code.

For the moment just to be paranoid I've created an /etc/hosts.allow and /etc/hosts.deny and locked all my services down to known IP numbers. This is of course a pain if you or your users are on the road.

Have fun,
Shay
--
=========================== Shay  Telfer ================================
 Perth, Western Australia   Technomancer  Join Team Sungroper, race the
 Opinions for hire              [POQ]     2003 World Solar Challenge
 [EMAIL PROTECTED]         fnord     <http://sungroper.asn.au/>