OpenSSH 3.x & Apache 1.3.x security fix

OpenSSH 3.x & Apache 1.3.x security fix

Post by RaNm » Mon, 01 Jul 2002 06:53:58



Did someone (BULL?) released a patch version for OpenSSH 3.X or a full
3.4 in LPP format for 4.3.2, 4.3.3.and 5.1L ?
Same question for Apache 1.3.26...

--
Vincent Jamart
UNIX/Oracle System Engineer
Systemat Computers Luxembourg S.A.

 
 
 

OpenSSH 3.x & Apache 1.3.x security fix

Post by Jan-Frode Myklebus » Mon, 01 Jul 2002 23:24:09



Quote:> Did someone (BULL?) released a patch version for OpenSSH 3.X or a full
> 3.4 in LPP format for 4.3.2, 4.3.3.and 5.1L ?
> Same question for Apache 1.3.26...

  For openssh the emergency fix is probably trivial (unless
  you use these features), just put these two lines into
  your sshd_config:

        ChallengeResponseAuthentication no
        PAMAuthenticationViaKbdInt no

  or else the OpenSSH 3.4 packages can be retrieved from
  Darren Tucker's OpenSSH Page:

        http://www.zip.com.au/~dtucker/openssh/

  -jf