OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [RHSA-2003:279-01] Updated OpenSSH packages fix potential vulnerability

From: Frank Knobbe (frankknobbe.us)
Date: Tue Sep 16 2003 - 14:27:09 CDT


Great.

So RedHat says the SSH issue is exploitable. FreeBSD says it is not
believed to be exploitable. And I believe Theo said the same for
OpenBSD. Is RedHat just scare mongering? Is there any proof of
exploitation (other than a Dos)? Does someone have a proof of all those
alleged exploitations going on all around world? Is the sky falling
again?

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (FreeBSD)

iD8DBQA/Z2QNpo+MRgtrF98RAmMGAKCz+Isb45QFyossTjKFyQ+tLvDYEgCgvmB+
MXj/eZayiFei3qI/by5tAho=
=kpYg
-----END PGP SIGNATURE-----