BugTraq
OPENSSH-SORCERER2003-09-17 Sep 17 2003 09:19AM
Michael Walton (mwalton abilene com) (1 replies)

Sorcerer Update Advisory
Tap Into the Source


________________________________________________________________________

Source Name: openssh-3.7p1
Advisory ID: SORCERER2003-09-17
Date: September 17th, 2003
________________________________________________________________________

Problem Description:
Versions of ssh before 3.7 are affected by a buffer management
bug. A problem in the openssh buffer.c file was found that
may or may not be exploitable. The sources have been updated
to protect the innocent.

Update:
Sources have been updated to the latest version.
________________________________________________________________________

Updated Sources: openssh-3.7p1


________________________________________________________________________

Recomendation:
augur synch && augur newer && augur update

or

augur easy



------------------------------------------------------------------------

Contacts:

Email: sorcerer-security (at) linuxmountain (dot) org [email concealed]
Mail List:
https://lists.berlios.de/mailman/listinfo/sorcerer-spells
Web: http://sorcerer.wox.org

--
Michael Walton, CCNA
Network Analyst
Leapfrog Technologies LLC
Bitstreet Internet
Cova Systems

mwalton (at) abilene (dot) com [email concealed]

[ reply ]
openssh 3.7.1 patched or not? Sep 17 2003 10:29PM
Tom Brown (tbrown baremetal com) (2 replies)
Re: openssh 3.7.1 patched or not? Sep 18 2003 06:57AM
Thomas Lotterer (thl dev de cw com)
Re: openssh 3.7.1 patched or not? Sep 17 2003 10:55PM
Alex Lambert (alambert quickfire org)


 

Privacy Statement
Copyright 2010, SecurityFocus