I think you're OK. The new ssh packages primarily include stuff to check for (and reject?)
vulnerable keys. The old ssh code itself did not have any problems.
Posted May 14, 2008 16:09 UTC (Wed) by furball4 (guest, #52069)
[Link]
Thanks. I also noticed that the new package did regenerate host keys when the existing ones
ran afoul of the vulnerable key checker. I would have preferred if it had an option to
regenerate them anyway, but oh well, it's easy enough to do by hand.