OpenSSH security hole

Posted by: tman

OpenSSH security hole - 16/09/2003 11:42

If anybody uses OpenSSH then please go and read http://www.openssh.com/txt/buffer.adv
There's been a security hole discovered and you need to either patch the existing code or upgrade to 3.7
Posted by: ricin

Re: OpenSSH security hole - 16/09/2003 11:47

HAH. I was just about to post something about that.
Posted by: ricin

Re: OpenSSH security hole - 16/09/2003 12:31

A lot of the mirrors don't have the latest 3.6 CVS snapshot or 3.7. So here's a few mirrors:
http://www.splaq.com/ssh/
http://www.maxinux.com/SSH/
Posted by: tman

Re: OpenSSH security hole - 16/09/2003 17:07

heh. I was going to post this earlier but I didn't have a proper write up for it.

The OpenSSH hole is annoying as hell. It means that everybody has to suddenly go out and patch/upgrade untold numbers of systems as normally the SSH port would be open.

If you've not got enough time then firewalling the SSH port and only allowing authorised IP addresses (static only though!) to connect should mitigate some of the risk but it's best to upgrade still.
Posted by: ricin

Re: OpenSSH security hole - 16/09/2003 17:15

heh. I was going to post this earlier but I didn't have a proper write up for it.

Ditto. I didn't have the files up on the mirrors yet either.


The OpenSSH hole is annoying as hell. It means that everybody has to suddenly go out and patch/upgrade untold numbers of systems as normally the SSH port would be open.
If you've not got enough time then firewalling the SSH port and only allowing authorised IP addresses (static only though!) to connect should mitigate some of the risk but it's best to upgrade still.

Yep, big pain in the butt. Every one of my machines has SSH on it, eesh. So far I've got all but three of them patched/upgraded.
Posted by: tman

Re: OpenSSH security hole - 17/09/2003 07:50

Umm yeah... Even more of a pain... 3.7.1 is out and it fixes more bugs
Posted by: ricin

Re: OpenSSH security hole - 17/09/2003 10:17

Grrr. I'm all for keeping up to date, but sometimes it's just really annoying.
Posted by: tman

Re: OpenSSH security hole - 23/09/2003 14:29

You're going to love this... 3.7.1p2 is out. There is a PAM bug in the portable version. The OpenBSD version is apparently fine.
Posted by: ricin

Re: OpenSSH security hole - 23/09/2003 14:34

Yeah. Thankfully I don't use PAM. Anyway, my mirror is up to date (the maxinux.com one isn't mine).