[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: not in sid yet? - CERT Advisory CA-2003-24 Buffer Management Vulnerability in OpenSSH



On Wed, 2003-11-12 at 19:40, bruce edge wrote:
> Looks like this is only available in woody:
> http://www.cert.org/advisories/CA-2003-24.html
> http://www.debian.org/security/2003/dsa-382
> http://www.debian.org/security/2003/dsa-383
> 
> Is there no fix for sid yet?

What do you mean, it has been fixed in the current version of ssh
(3.6.1p2-9) The days they were announced there were fixes available (4
hours if I remember properly) (2 version increments in short order)

-- 
greg, greg@gregfolkert.net
REMEMBER ED CURRY! http://www.iwethey.org/ed_curry

Where it not for the dizzy whiptail ambivalence of your crumbling
fleece, I could never contemplate the ways of so many merchant bankers
in heat.

Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: