Re: OpenSSH security

2002-01-29 Thread David Talkington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Rilindo Foster wrote: >I saw that problem even with 2.9 version. When you say "saw that problem", do you mean that you were able to run the 'crc32 compensation attack detection vulnerability' against OpenSSH v2.9? If so, you should send details

Re: OpenSSH security

2002-01-28 Thread Rilindo Foster
I saw that problem even with 2.9 version. At any rate, it is probably a moot point if you are using protocol version 2. On Monday 28 January 2002 08:15 pm, you wrote: > Rilindo Foster wrote: > >Yes. Upgrade immediately. > > Could you please provide support for that? According to these details >

RE: OpenSSH security

2002-01-28 Thread David Talkington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Rilindo Foster wrote: >Yes. Upgrade immediately. Could you please provide support for that? According to these details from the developers: http://www.openssh.com/security.html this was a dead issue as of 2.3.0. Please correct me if I ve missed

RE: OpenSSH security

2002-01-28 Thread Rilindo Foster
Yes. Upgrade immediately. ---begin signature- Rilindo Foster http://monzell.com AIM: rilindo -end signature- -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of JW Sent: Tuesday, January 15, 2002 4:38 PM To: [EMAIL PROTECTED] Subj