Mailing-List: contact cygwin-help@cygwin.com; run by ezmlm
List-Subscribe: <mailto:cygwin-subscribe@cygwin.com>
List-Archive: <http://sources.redhat.com/ml/cygwin/>
List-Post: <mailto:cygwin@cygwin.com>
List-Help: <mailto:cygwin-help@cygwin.com>, <http://sources.redhat.com/ml/#faqs>
Sender: cygwin-owner@cygwin.com
Delivered-To: mailing list cygwin@cygwin.com
Delivered-To: fixup-cygwin@cygwin.com@fixme
From: "Paul G." <pgarceau@qwest.net>
Organization: Paul G.
To: cygwin@cygwin.com
Date: Fri, 14 Dec 2001 17:25:18 -0800
MIME-Version: 1.0
Subject: Re: Exploitation of vulnerability in SSH1 CRC-32 compensation
Reply-to: pgarceau@qwest.net
Message-ID: <3C1A35FE.21643.864CE1@localhost>
In-reply-to: <20011214113914.K740@cygbert.vinschen.de>
References: <3C19059B.21306.1306EC2@localhost>; from pgarceau@qwest.net on Thu, Dec 13, 2001 at 07:46:35PM -0800
X-mailer: Pegasus Mail for Windows (v4.01)
Content-type: text/plain; charset=US-ASCII
Content-transfer-encoding: 7BIT
Content-description: Mail message body



On 14 Dec 2001 at 11:39, Corinna Vinschen wrote:

> On Thu, Dec 13, 2001 at 07:46:35PM -0800, Paul G. wrote:
> > Hi folks, 
> > 
> > 	Not sure if this even applies for Cygwin, but thought I'd ask: 
> > 
> > 	SSH CRC32 attack detection code contains remote integer overflow 
> > 
> > 	Description:  http://www.kb.cert.org/vuls/id/945216 
> > 
> > 	Is the version of OpenSSH that is currently in use for Cygwin
> > vulnerable? 
> 
> http://www.kb.cert.org/CERT_WEB/vul-notes.nsf/id/JPLA-53TPWS

	Okey-dokey!  ;-)  (revision dated 12/13 -- ;-))
> 
> Corinna
> 
> -- 
> Corinna Vinschen                  Please, send mails regarding Cygwin
> to Cygwin Developer                               
> mailto:cygwin@cygwin.com Red Hat, Inc.
> 
> --
> Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
> Bug reporting:         http://cygwin.com/bugs.html
> Documentation:         http://cygwin.com/docs.html
> FAQ:                   http://cygwin.com/faq/
> 
> 



--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Bug reporting:         http://cygwin.com/bugs.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

