LWN.net Logo

OpenSSH 3.2.2 fixes multiple vulnerabilities

Package(s):openssh CVE #(s):
Created:June 5, 2002 Updated:June 5, 2002
Description: The OpenSSH developers have released OpenSSH 3.2.2. Security fixes in this release are: "
- fixed buffer overflow in Kerberos/AFS token passing
- fixed overflow in Kerberos client code
- sshd no longer auto-enables Kerberos/AFS
- experimental support for privilege separation [...]
- only accept RSA keys of size SSH_RSA_MINIMUM_MODULUS_SIZE (768) or larger"

(First LWN report: May 23).
Alerts:
Eridani ERISA-2002:017 2002-05-23

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds