看板FB_security
標 題De Raadt + FBSD + OpenSSH + hole?
發信站NCTU CS FreeBSD Server (Mon Apr 14 09:27:25 2014)
轉信站ptt!csnews.cs.nctu!news.cednctu!FreeBSD.cs.nctu!.POSTED!freebsd.org!ow
Hi everyone,
I came across this :
https://groups.google.com/forum/#!topic/mailing.openbsd.tech/xALfxxR3oKo
" You are welcome. Stuart Henderson wrote the draft, but he forgot that
part, and Damien Miller and I realized it was needed. We sensed there
might be some ambiguity... we'll take care the next time an
OpenOffice problem also.
.... as long as you aren't using FreeBSD or a derivative (hint: Jupiper),
you are fine. That's the only place I know of an OpenSSH hole.
Oh now I sense some angst. Please ask Kirk McKusick, he knows the
story about why this is not being disclosed to FreeBSD. Sometimes I
feel a bit sorry for them (and for him), but then the next minute I
don't feel sorry because there's damn good reasons they won't be
told about what I found.
Does that answer help? Hope so."
Any guidance here?
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"