[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [d-security] Re: ssh vulnerability in the wild



Hello there,

Christian Hammers schrieb:
> 
> On Tue, Sep 16, 2003 at 04:00:30PM +0100, Thomas Horsten wrote:
> > On Tue, 16 Sep 2003, Alexander Neumann wrote:
> >
> > > According to Wichert, the security team is already working on an update.
> 
> The new version has already been installed. This was quick. Good work,
> security team.
> 
>  openssh (1:3.4p1-1.1) stable-security; urgency=high
> 
>   * NMU by the security team.
>   * Merge patch from OpenBSD to fix a security problem in buffer handling
> 
>  -- Wichert Akkerman <wakkerma@debian.org>  Tue, 16 Sep 2003 13:06:31 +0200

So only one problem remains: The version in woody-proposed-updates is
1:3.4p1-1.woody.1 which is "newer" than the patched version. So I had to
manually "downgrade" my proposed-updates-version to get the fix.
(apt-get dist-upgrade didn't show any packages to upgrade)
When will there be a "new" version in proposed-updates for apt-getting
the fix?

bye,
Matthias Merz

Attachment: smime.p7s
Description: Kryptographische Unterschrift mit S/MIME


Reply to: