Re: Exploitation of vulnerability in SSH1 CRC-32 compensation

2001-12-14 Thread Paul G.
On 14 Dec 2001 at 11:39, Corinna Vinschen wrote: > On Thu, Dec 13, 2001 at 07:46:35PM -0800, Paul G. wrote: > > Hi folks, > > > > Not sure if this even applies for Cygwin, but thought I'd ask: > > > > SSH CRC32 attack detection code contains remote integer overflow > > > > Des

Re: Exploitation of vulnerability in SSH1 CRC-32 compensation

2001-12-14 Thread Corinna Vinschen
On Thu, Dec 13, 2001 at 07:46:35PM -0800, Paul G. wrote: > Hi folks, > > Not sure if this even applies for Cygwin, but thought I'd ask: > > SSH CRC32 attack detection code contains remote integer overflow > > Description: http://www.kb.cert.org/vuls/id/945216 > > I

Exploitation of vulnerability in SSH1 CRC-32 compensation

2001-12-13 Thread Paul G.
Hi folks, Not sure if this even applies for Cygwin, but thought I'd ask: SSH CRC32 attack detection code contains remote integer overflow Description: http://www.kb.cert.org/vuls/id/945216 Is the version of OpenSSH that is currently in use for Cygwin vulner