(fwd) OpenSSH trojan!


I have no idea if this affects Debian in any way, shape, or form
-- but better safe than sorry, so here it is FYI...


WARNING:  The openssh-3.4p1.tar.gz on the openssh.org site is trojaned.
I downloaded it and verified it.  Better check the md5sum on
your openssh-3.4p1.tar.gz.

Good version: 459c1d0262e939d6432f193c7a4ba8a8  openssh-3.4p1.tar.gz
Bad version:  3ac9bc346d736b4a51d676faa2a08a57  openssh-3.4p1.tar.gz


According to what I jhust read here:


You may wish to scrub everything down.


Reply to: