Firewall Wizards mailing list archives

RE: Looking for "lease based popper access"


From: Jan van Rensburg <devnull () epiuse com>
Date: Wed, 15 Dec 1999 16:33:43 +0200

that's correct. RSAREF has an exploitable problem (exploit code released
yesterday for ssh-1.2.27).
RSA no longer maintains the original freeware RSAREF. they do however give
you permission to edit the code to fix this specific problem (according to
the cert advisory). generally people outside of the USA don't have to worry,
'cause they're not linked against RSAREF. for once the USA crypto laws did
serve a good purpose (unintentionally). see the latest bugtraq archives
(http://www.securityfocus.com) for information on fixing the problem.

--fungai

Yep all those aplications built with RSA are now
exploitable, so, has a pacht been released that addresses 
this and allows
folks to patch RSAREF then rebuild all the applications that use it?




Current thread: