[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: CVE-2006-0883 - are we vuln?



Jan Luehr wrote:
>> > can you confirm or deny, that we're effected by CVE-2006-0883 (SSH-DoS)?
>> > I haven't found any suitable information yet.
>> > Since only freebsd released a fix (afaik) I don't even know, if any linux
>> > builts are  exploitable.
>>
>> It's fixed since ages in Debian, in 3.8.1p1-4, Woody isn't affected.
>
> Thanks - do you know the dsa number, too?

There's no DSA, it was fixed before Sarge froze and Woody isn't affected.

> I haven't seen any dsa regarding openssh this year. (Well, it's CVE-2006, thus 
> I think it've been found this year, haven't it?

It was discovered in 2004, normally it should've been a CVE-2004-XXXX.

Cheers,
        Moritz



Reply to: