[plug] OpenSSH and security holes

Leon Brooks leonb at bounce.networx.net.au
Thu Dec 9 22:09:48 WST 1999


Matt Kemner wrote:
> On Wed, 8 Dec 1999, Leon Brooks wrote:

>>> with RSAREF enabled...

>> Just bugs, or *ghasp* security holes?

> Security holes.

> "For SSH up to 1.2.27 compiled with RSAREF2 this implies the remote
> execution of arbitrary commands as root."

OpenSSH as well, or just regular ssh?


More information about the plug mailing list