[GECOS] island report with upcoming issues (fwd)

Michael Bell michael.bell at stanford.edu
Wed Apr 30 12:20:33 PDT 2003


I originally installed regular SSH, but I haven't looked at it in quite
a while.


-----Original Message-----
From: Bill Murray [mailto:bmurray at snf.stanford.edu] 
Sent: Wednesday, April 30, 2003 10:31 AM
To: computer at snf.stanford.edu
Subject: [GECOS] island report with upcoming issues (fwd)


Are we using OpenSSH?


---------- Forwarded message ----------
Date: Wed, 30 Apr 2003 10:04:17 -0700
From: Joe Little <jlittle at cs.stanford.edu>
To: gecos at island.stanford.edu
Subject: [GECOS] island report with upcoming issues


Today's article, linked to above, covers an HPUX issue, MySQL issues,  
and most importantly, an issue present in OpenSSH that likely will  
involve updates for all OpenSSH-enabled systems. The attack vector to  
OpenSSH ties into weak passwords, and such an attack would be overly  
noisy. However, I still recommend updating systems when an update is  
available from your vendor. A current workaround is presented as well.

GECOS mailing list
GECOS at island.stanford.edu

More information about the computer mailing list