Thread
:
Does the Debian SSH vulnerability apply?
View Single Post
bitmage
2008-05-20 , 20:05
Posts: 7 | Thanked: 4 times | Joined on Nov 2005
#
3
I contacted the package maintainer and received the following response:
According to DSA you've mentioned first vulnerable version of openssl
was 0.9.8c-1.
Fortunately maemo distro has older version - 0.9.7e-4. You can see it
in their pool for maemo4.0/chinook distro, which is used in N810:
http://repository.maemo.org/pool/mae...ree/o/openssl/
You can also check it on your device with dpkg -l openssl command.
So, I think openssh is not affected by this vulnerability.
The dpkg command didn't work for me, but going into redpill mode allowed me to verify that the libssl is 0.9.7e-4.osso2+3sarge3.osso6.
Quote & Reply
|
The Following User Says Thank You to bitmage For This Useful Post:
Faz
bitmage
View Public Profile
Send a private message to bitmage
Find all posts by bitmage