-------- Original Message --------

> Usually, audits allow for notifying as a false positive as scanning tools 
> often
> have false positives or technical vulnerabilities that aren't exploitable.
> 
> It sounds like these are all false positives unless your servers ssh client is
> connecting to some oddly managed server.

To further the point. Debian stables security team routinely marks packages as
unaffected by a CVE or other language along the lines of rare or very unlikely
to be an issue whilst updating the package in unstable. You could ask them about
Debian stable servers as surely they would have not required unstable to be 
used.

-- 
All the best,
             Kevin Chadwick

Reply via email to