Re: Updated: OpenSSH-3.7p1-1

2003-09-16 Thread Tony Schmitt
Thanks! Corinna Vinschen wrote on 9/16/2003, 6:32 PM: > I've just updated the version of OpenSSH to 3.7p1-1. > > This is an official new release as of yesterday. The Cygwin version > is from the vanilla sources with just one tiny patch (my bad). > > Official Release Message: > ===

new openssh vulnerability

2003-09-16 Thread Tony Schmitt
Corinna - I was informed of an SSH hole today. Referring to http://www.securityfocus.com/advisories: "...a buffer management error found in versions of OpenSSH earlier than 3.7. The possibility exists that this error could allow a remote exploit..." Were you aware of this? Thanks, To