D&C Lug - Home Page
Devon & Cornwall Linux Users' Group

[ Date Index ][ Thread Index ]
[ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] [SECURITY] [DSA-134-1] OpenSSH remote vulnerability



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Tuesday 25 June 2002 10:26 am, Simon Waters wrote:

Seems ISS treat them better than the Apache team, or maybe they
learnt their lesson?

ISS are not in my good books at the moment, imho they acted toally 
irresposibly with the apache vunrability... (though i know there has been 
tension between the ISS and AFS, along wiht Redhat for some time)

Haven't seen anything suggesting the Apache bug is exploitable
on Linux, but I wouldn't take the chance.

it only results in a segfault right now, but not long before someone manages 
to get it to execute code.  still, a dos attack is bad enough.


~ theo

- -- 

Theo Zourzouvillys
http://zozo.org.uk/

You will be honored for contributing your time and skill to a worthy cause.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

iD8DBQE9GFCn448CrwpTn6YRAtqSAKD2oUgUGxuWuVn2Gljm1YDlm+/1OACfR9KV
FqzwmYFgwwUfloGxmQFp7V8=
=gw9g
-----END PGP SIGNATURE-----


--
The Mailing List for the Devon & Cornwall LUG
Mail majordomo@xxxxxxxxxxxx with "unsubscribe list" in the
message body to unsubscribe.


Lynx friendly