[lug] SSH Vulnerability

Nate Duehr nate at natetech.com
Fri Feb 9 10:55:32 MST 2001


Slashdot and other sources are reporting that there is a new published
exploit for pretty much all versions of SSH, not including OpenSSH
2.4.0.

The page below also details various vendor responses with F-Secure being
the worst.  (No response at all so far back to the reporting party.)

Here's the people reporting it:

http://razor.bindview.com/publish/advisories/adv_ssh1crc.html

-- 
Nate Duehr <nate at natetech.com>

GPG Key fingerprint = DCAF 2B9D CC9B 96FA 7A6D AAF4 2D61 77C5 7ECE C1D2
Public Key available upon request, or at wwwkeys.pgp.net and others.



More information about the LUG mailing list