[2461] in SIPB_Linux_Development
Re: ssh in 5.2
daemon@ATHENA.MIT.EDU (Aaron M. Ucko)
Tue Feb 2 23:39:03 1999
To: Erik Nygren <nygren@MIT.EDU>
Cc: linux-dev@MIT.EDU
From: amu@MIT.EDU (Aaron M. Ucko)
Date: 02 Feb 1999 23:38:47 -0500
In-Reply-To: Erik Nygren's message of "Tue, 02 Feb 1999 23:37:09 EST"
Erik Nygren <nygren@MIT.EDU> writes:
> RedHat Linux-Athena 5.2 is still using ssh 1.2.23 for
> /usr/athena/bin/ssh*. How hard would it be to merge in the latest
> 1.2.* version? (Am I right in remembering somewhere that there are
> some holes/weaknesses in 1.2.23? A thread on net-defense seems to
> imply that at least one variant of the kerberos support in ssh
> prior to 1.2.26 has some buffer-overruns. Is this a problem for us?
(SIPB-)Athena took all the security bug fixes.
--
Aaron M. Ucko, KB1CJC <amu@mit.edu> (finger amu@monk.mit.edu)