Re: New sshd exploits...

2001-02-10 Thread Ethan Benson
On Sat, Feb 10, 2001 at 04:23:46PM -0800, Joey Hess wrote: > Ethan Benson wrote: > > i just wish the libc fix would come out soon :( (LD_PRELOAD file > > overwrite thing) > > http://www.debian.org/News/weekly/2001/3/mail#1 different bug, this message refers to the RESOLV_HOST_CONF variable bug w

Re: New sshd exploits...

2001-02-10 Thread Joey Hess
Ethan Benson wrote: > i just wish the libc fix would come out soon :( (LD_PRELOAD file > overwrite thing) http://www.debian.org/News/weekly/2001/3/mail#1 -- see shy jo

Re: New sshd exploits...

2001-02-10 Thread Ethan Benson
On Fri, Feb 09, 2001 at 08:49:20PM -0500, Jonathan D. Proulx wrote: > On Fri, Feb 09, 2001 at 04:33:25PM -0900, Ethan Benson wrote: > > :there was a ssh update to stable yesterday with the following fixes: > : > :openssh (1:1.2.3-9.2) stable; urgency=high > : > : * Non-maintainer upload by Securi

Re: New sshd exploits...

2001-02-09 Thread Jonathan D. Proulx
On Fri, Feb 09, 2001 at 04:33:25PM -0900, Ethan Benson wrote: :there was a ssh update to stable yesterday with the following fixes: : :openssh (1:1.2.3-9.2) stable; urgency=high : : * Non-maintainer upload by Security Team : * Added backported fix for a buffer overflow (thanks to Piotr :Rosz

Re: New sshd exploits...

2001-02-09 Thread Ethan Benson
On Fri, Feb 09, 2001 at 08:14:08PM -0500, Jonathan D. Proulx wrote: > Hi, > > I've only seen one (rather obscure) message to debian lists about this > one, but there are 2 new exploits out for sshd > > this one is not much to loose sleep about as it's rather tricky and > OpenSSH claims that it's

New sshd exploits...

2001-02-09 Thread Jonathan D. Proulx
Hi, I've only seen one (rather obscure) message to debian lists about this one, but there are 2 new exploits out for sshd this one is not much to loose sleep about as it's rather tricky and OpenSSH claims that it's not exploitable though they have patched their source tree as of Jan 29, 2001: ht