Full Disclosure mailing list archives

Re: new ssh exploit?


From: Valdis.Kletnieks () vt edu
Date: Tue, 16 Sep 2003 16:45:05 -0400

On Tue, 16 Sep 2003 13:13:51 EDT, "Jonathan A. Zdziarski" <jonathan () nuclearelephant com>  said:
Does anyone know if this vulnerability is present in the free
noncommercial ssh distribution from ssh.fi?

Looking at the relevant code in ssh 3.2.5, it appears not, as the ssh.com code
was already using a temp variable the same way that the openssh code added one.


Attachment: _bin
Description:


Current thread: