They're quite old, and hence vulnerable.  I agree that if Pat's company paid
for support after the install that DSG should be able to provide them with
updated versions.  I've probably got newer versions laying around for SuSE
7.0 myself.  I should probably go look for them.

Mark Post

-----Original Message-----
From: Adam Thornton [mailto:athornton@;sinenomine.net]
Sent: Tuesday, November 12, 2002 5:41 PM
To: [EMAIL PROTECTED]
Subject: Re: Use SSH instead of TELNET


On Tue, Nov 12, 2002 at 02:46:42PM -0500, Abruzzese, Pat wrote:
> I running SuSE 7.0 (s390) Kernel 2.2.16 this is not from Marist. It was
> installed by Denver Solutions for me.

Unless you explicitly have no post-installation support from Denver
Solutions, you should also probably get your money's worth by asking
them about it.  Although Mark has identified the issue and where to get
the appropriate RPMs.  OpenSSH went through a spate of vulnerabilities
though, and I don't know offhand if the ones there are secure or not.
Ideally you want one of the 3.x OpenSSH versions with privilege
separation.

Adam

Reply via email to