또 보안버그로 인해 새버전이 나왔습니다.
overflow관련 보안버그이니 어서 업그레이드 하세요 -_-;;
관련링크는 Openssh메일링 리스트입니다. 가입 필요없이 기존의
메일링 내용을 볼수있고 검색도 가능하니 방문해보세요.
-=-=-=-=-=-=-=-==-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
List: secure-shell
Subject: OpenSSH 3.4 released
From: Markus Friedl <Markus_Friedl@genua.de>
Date: 2002-06-26 14:40:33
OpenSSH 3.4 has just been released. It will be available from the
mirrors listed at http://www.openssh.com/ shortly.
OpenSSH is a 100% complete SSH protocol version 1.3, 1.5 and 2.0
implementation and includes sftp client and server support.
We would like to thank the OpenSSH community for their continued
support and encouragement.
Changes since OpenSSH 3.3:
============================
Security Changes:
=================
All versions of OpenSSH's sshd between 2.9.9 and 3.3
contain an input validation error that can result in
an integer overflow and privilege escalation.
OpenSSH 3.4 fixes this bug.
In addition, OpenSSH 3.4 adds many checks to detect
invalid input and mitigate resource exhaustion attacks.
OpenSSH 3.2 and later prevent privilege escalation
if UsePrivilegeSeparation is enabled in sshd_config.
OpenSSH 3.3 enables UsePrivilegeSeparation by
default.
Reporting Bugs:
===============
- please read http://www.openssh.com/report.html
and http://bugzilla.mindrot.org/
-=-=-=-=-=-=-=-==-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
관련 링크: http://marc.theaimsgroup.com/?l=secure-shell&r=1&w=2
'Security' 카테고리의 다른 글
원격침입과 도스공격이 가능한 PHP 취약점 (0) | 2002.07.23 |
---|---|
libbind(BIND) 의 보안버그(buffer overflow) (0) | 2002.07.03 |
Openssh 취약점 및 PrivilegeSeparation (1) | 2002.06.27 |
Apache Web Server Chunk Handling 취약점 (0) | 2002.06.20 |
Sendmail 메일서버의 스팸릴레이 대응방법 (0) | 2002.06.10 |