Hi Michael,
Do you know where these patches can be found? They don't seem to be at
the ftp://ftp.ssh.com/pub/ssh/ site.
Thanks Carl
On 03-May-00 Michael H. Warfield wrote:
> On Wed, May 03, 2000 at 04:07:12PM -0400, asosin wrote:
>> Does anyone know where we can download the RPM of the ssh-1.2.27
(US)
>> version for Linux ?
>
> Why?
>
> Ssh-1.2.27 for the US had a couple of bugs. The US version
required
> RSAREF2 from RSALABS and used the rsaglue file to access it. A buffer
> overflow was uncovered in rsaglue.c and then one was discovered in
> RSAREF2. You need to apply BOTH patches or you have two security
> holes.
>
> There is also OpenSSH up at www.openssh.com. RPM's are available
> and there are versions for the SSH version 1 protocol and a beta
> version
> that includes the SSH version 2 protocol.
>
>> Thnkx.
>
> Mike
> --
> Michael H. Warfield | (770) 985-6132 | [EMAIL PROTECTED]
> (The Mad Wizard) | (770) 331-2437 |
> http://www.wittsend.com/mhw/
> NIC whois: MHW9 | An optimist believes we live in the best of
> all
> PGP Key: 0xDF1DD471 | possible worlds. A pessimist is sure of it!
------------------------------------------------------------------------
E-Mail: Carl J. Nobile <[EMAIL PROTECTED]>
Date: 12-Jun-00 Phone: 315-453-2912 Ex. 5336
Time: 14:30:52 Fax: 315-479-0859
Software Engineering Group -- AppliedTheory Corp.
224 Harrison Street, 6th Floor, Syracuse, NY 13202
------------------------------------------------------------------------