 |
 |
Why OpenSSH 3.6.1p1 with Panther?
|
 |
|
 |
|
Mac Elite
Join Date: Feb 2002
Location: Hilton Head, SC
Status:
Offline
|
|
Shouldn't this be updated/patched? OpenSSH 3.6.1p1 has known vulnerablilities.
|
|
|
| |
|
|
|
 |
|
 |
|
Addicted to MacNN
Join Date: Mar 2000
Location: London, UK
Status:
Offline
|
|
What vulnerabilities?
Apple distributes OpenSSH 3.6.1p1 + patches to resolve known vulnerabilities
CAN-2003-0693 was resolved in 10.2.8 (ssh -V reports OpenSSH_3.4p1+CAN-2003-0693)
CAN-2004-0175 was resolved in Security Update 2004-09-07 (ssh -V reports OpenSSH_3.6.1p1+CAN-2004-0175)
OpenSSH 3.6.1p1 is not affected by CAN-2003-0682.
|
|
|
| |
|
|
|
 |
|
 |
|
Mac Elite
Join Date: Feb 2002
Location: Hilton Head, SC
Status:
Offline
|
|
I guess my scanner was assuming by the name that it was the unpatched version. I do know that at least here at IBM SSH1 is being totally disco'd in favor of SSH2.
|
|
|
| |
|
|
|
 |
|
 |
|
Addicted to MacNN
Join Date: Mar 2000
Location: London, UK
Status:
Offline
|
|
Originally posted by Tyler McAdams:
I guess my scanner was assuming by the name that it was the unpatched version. I do know that at least here at IBM SSH1 is being totally disco'd in favor of SSH2.
OpenSSH supports SSH2.
|
|
|
| |
|
|
|
 |
|
 |
|
Mac Elite
Join Date: Feb 2002
Location: Hilton Head, SC
Status:
Offline
|
|
Originally posted by Angus_D:
OpenSSH supports SSH2.
Right... ssh -2
|
|
|
| |
|
|
|
 |
|
 |
|
Posting Junkie
Join Date: Nov 2000
Location: in front of my Mac
Status:
Offline
|
|
|
|
|
•
|
| |
|
|
|
 |
|
 |
|
Mac Elite
Join Date: Feb 2002
Location: Hilton Head, SC
Status:
Offline
|
|
Originally posted by Simon:
No idea why Apple is sticking to 3.6.1p1. Although, I don't know if the vulnerabilities of 3.6.x apply to Mac OS X as well.
It sounds as if it's been patched... but you would think they would rename it... 
|
|
|
| |
|
|
|
 |
|
 |
|
Addicted to MacNN
Join Date: Mar 2000
Location: London, UK
Status:
Offline
|
|
Originally posted by Tyler McAdams:
It sounds as if it's been patched... but you would think they would rename it...
They have. Look at ssh -V
They haven't bumped the version number because the upstream version hasn't changed.
|
|
|
| |
|
|
|
 |
 |
|
 |
|
|
|
|
|

|
|
 |
Forum Rules
|
 |
 |
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
|
HTML code is Off
|
|
|
|
|
|
 |
 |
 |
 |
|
 |