[2461] in SIPB_Linux_Development

home help back first fref pref prev next nref lref last post

Re: ssh in 5.2

daemon@ATHENA.MIT.EDU (Aaron M. Ucko)
Tue Feb 2 23:39:03 1999

To: Erik Nygren <nygren@MIT.EDU>
Cc: linux-dev@MIT.EDU
From: amu@MIT.EDU (Aaron M. Ucko)
Date: 02 Feb 1999 23:38:47 -0500
In-Reply-To: Erik Nygren's message of "Tue, 02 Feb 1999 23:37:09 EST"

Erik Nygren <nygren@MIT.EDU> writes:

> RedHat Linux-Athena 5.2 is still using ssh 1.2.23 for
> /usr/athena/bin/ssh*.  How hard would it be to merge in the latest
> 1.2.* version?  (Am I right in remembering somewhere that there are
> some holes/weaknesses in 1.2.23?  A thread on net-defense seems to
> imply that at least one variant of the kerberos support in ssh 
> prior to 1.2.26 has some buffer-overruns.  Is this a problem for us?

(SIPB-)Athena took all the security bug fixes.

-- 
Aaron M. Ucko, KB1CJC <amu@mit.edu> (finger amu@monk.mit.edu)

home help back first fref pref prev next nref lref last post