Re: FreeBSD Security Advisory FreeBSD-SA-15:22.openssh

2015-08-27 Thread Dag-Erling Smørgrav
Mike Tancsa writes: > I know RELENG_8 is no longer supported, but does this issue impact > FreeBSD 8.x ? Note that of the three issues mentioned here, one is not exploitable by an attacker and the other two presuppose a compromised pre-auth child. DES -- Dag-Erling Smørgrav - d...@des.no __

Re: FreeBSD Security Advisory FreeBSD-SA-15:22.openssh

2015-08-27 Thread Mike Tancsa
On 8/27/2015 3:24 AM, Dag-Erling Smørgrav wrote: > Mike Tancsa writes: >> I know RELENG_8 is no longer supported, but does this issue impact >> FreeBSD 8.x ? > > Note that of the three issues mentioned here, one is not exploitable by > an attacker and the other two presuppose a compromised pre-au

Re: FreeBSD Security Advisory FreeBSD-SA-15:22.openssh

2015-08-27 Thread Borja Marcos
On Aug 27, 2015, at 3:08 PM, Mike Tancsa wrote: > On 8/27/2015 3:24 AM, Dag-Erling Smørgrav wrote: > For the latter two, I am trying to understand in the context of a shared > hosting system. Could one user with sftp access to their own directory > use these bugs to gain access to another user's

Re: FreeBSD Security Advisory FreeBSD-SA-15:22.openssh

2015-08-27 Thread Peter Pentchev
On Thu, Aug 27, 2015 at 03:19:04PM +0200, Borja Marcos wrote: > > On Aug 27, 2015, at 3:08 PM, Mike Tancsa wrote: > > > On 8/27/2015 3:24 AM, Dag-Erling Smørgrav wrote: > > For the latter two, I am trying to understand in the context of a shared > > hosting system. Could one user with sftp access

Re: FreeBSD Security Advisory FreeBSD-SA-15:22.openssh

2015-08-27 Thread Dag-Erling Smørgrav
Mike Tancsa writes: > For the latter two, I am trying to understand in the context of a shared > hosting system. Could one user with sftp access to their own directory > use these bugs to gain access to another user's account ? Once again: both of these are attacks on the main sshd process by the

sendmail server sending milter data after latest FreeBSD upgrade

2015-08-27 Thread Robert Sargent via freebsd-security
Hi, After rebuilding my systems after the latest openssl/iret handler I noticed some incoming email sessions were failing. The failures were primarily from hotmail.com, outlook.com, google.com and me.com. The SMTP server [sendmail v 8.15.2] logs contained lines like this: Aug 27 14:41:22 tu