[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: openssh version info bug or feature ?



On Thu, Feb 07, 2002 at 12:21:06AM +1100, Paul Hampson wrote:
> On Wed, Feb 06, 2002 at 08:11:44AM -0500, Anthony DeRobertis wrote:
> > I'd just worry that existing network audits will be thrown off 
> > by changing the version. I _do_ think we should change the 
> > version when we release a security fix, though. Or when we make 
> > major changes (not sure if we do for ssh).
> 
> That's pretty much it in a nutshell.

Um. Just to clarify, this is *NOT* a change in the version number. It's
a change in the RFC-compliant *comment field*. Any scanner that's
confused by that has real issues, *especially* since the next version of
openssh will probably make that string a config file item.

-- 
Mike Stone



Reply to: