Julian Elischer <[EMAIL PROTECTED]> writes: > So, the fix would be to go back to an old version of ssh?
Yes, but you'd have to go back to a version with known remotely exploitable vulnerabilities. Since this is a problem for you and your customers, I will look into getting password changing to work, at least for PAM authentication, when I import 3.6 (which should be out in a few weeks). DES -- Dag-Erling Smørgrav - [EMAIL PROTECTED] To Unsubscribe: send mail to [EMAIL PROTECTED] with "unsubscribe freebsd-hackers" in the body of the message