[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[ale] ssh remote root exploit :-(
- Subject: [ale] ssh remote root exploit :-(
- From: dhurst at kennesaw.edu (Dow Hurst)
- Date: Tue, 25 Jun 2002 19:03:28 -0400
From the letter posted it sounds like we need to put pressure on our
vendors to help out the OpenSSH developers.
Dow
Jonathan Rickman wrote:
>Everyone should be aware that this new version does not fix the
>vulnerability. It only reduces the risk since the attacker can only
>gain access to the sshd account due to the new priveledge separation
>feature. This could still ruin your day if your system is miles away and
>ssh is your only means of accessing it.
>
>Just a reminder not to get too comfortable yet :)
>
>
>
>
---
This message has been sent through the ALE general discussion list.
See http://www.ale.org/mailing-lists.shtml for more info. Problems should be
sent to listmaster at ale dot org.