Bugtraq mailing list archives

Re: [Fwd: Truth about ssh 1.2.27 vulnerabiltiy]


From: iglesias () DRACO ACS UCI EDU (Mike Iglesias)
Date: Tue, 28 Sep 1999 14:24:05 -0700


A trivial demo program that demonstrates the problem is attached.  (It
needs no special privileges; run it as an unprivileged user in any
writable directory.)  The program reports "okay" under Solaris 2.5.1 and
IRIX 6.5.2, "vulnerable" under RedHat 6.

According to your program, Digital Unix 4.0B, 4.0D, and Tru64 Unix 4.0F
are all vulnerable.

Mike Iglesias                        Internet:    iglesias () draco acs uci edu
University of California, Irvine     phone:       949-824-6926
Office of Academic Computing         FAX:         949-824-2069


Current thread: