version 1.398, 2002/06/26 06:10:48 |
version 1.399, 2002/06/26 11:01:06 |
|
|
<p> |
<p> |
<a name=sshd></a> |
<a name=sshd></a> |
<li><font color=#009000><strong>006: SECURITY FIX: June 24, 2002</strong></font><br> |
<li><font color=#009000><strong>006: SECURITY FIX: June 24, 2002</strong></font><br> |
An (as yet) undisclosed bug exists in OpenSSH which a patch is not forthcoming |
An (as yet) undisclosed bug exists in OpenSSH, which a patch is not forthcoming |
for yet -- no patch exists yet!<br> |
for yet -- no patch exists yet!<br> |
However, upgrading to <a href="http://www.openssh.com/openbsd.html">OpenSSH 3.3</a> |
However, upgrading to <a href="http://www.openssh.com/openbsd.html">OpenSSH 3.3</a> |
with the <strong>UsePrivilegeSeparation</strong> option enabled will block this |
with the <strong>UsePrivilegeSeparation</strong> option enabled will block this |
problem.<br> |
problem.<br> |
All users are advised to update immediately, and keep an eye out for |
All users are advised to update immediately, and keep an eye out for |
a upcoming OpenSSH 3.4 release on Monday containing a real fix. |
an upcoming OpenSSH 3.4 release on Monday containing a real fix. |
<p> |
<p> |
<a name=httpd></a> |
<a name=httpd></a> |
<li><font color=#009000><strong>005: SECURITY FIX: June 19, 2002</strong></font><br> |
<li><font color=#009000><strong>005: SECURITY FIX: June 19, 2002</strong></font><br> |