C'est ce qu'on peut lire dans cette alerte de idefense.com :
http://idefense.bugtraq.org/adv/05.03.04.txt(...)
There is an upcoming OpenSSH vulnerability that we're working on with
the OpenBSD Crew. Details will be published early next week.
However, I can say that when OpenSSH's sshd(8) is running with priv
seperation, the bug cannot be exploited for immediate root access.
Donc si vous ne l'avez pas encore fait, pensez à activer UsePrivilegeSeparation :)
iDEFENSE recommends either using OpenBSD, Openwall Linux (Owl), or
Microsoft Windows. All (…)
Journal Une faille dans OpenSSH ?
3
mai
2004