OpenSSH Security Advisory (adv.iss)
Posted Jun 26, 2002 15:47 UTC (Wed) by
garloff (subscriber, #319)
Parent article:
OpenSSH Security Advisory (adv.iss)
I'm unimpressed by the handling of this from the OpenSSH team.
Given the seriousness of the problem, I do understand why Theo
wanted distributors to upgrade to 3.3 (and enable PrivSep) before
publishing the vulnerability.
I do not understand why the bugfix has not been communicated to
the Linux distributors before publishing it. Normally that happens.
The different distributors could have coordinated their updates
and released their advisories shortly after the publication from
the OpenSSH team.
Basically, the message I read from this procedure is
"We BSD people don't care about you Linux people."
(
Log in to post comments)