> Is there a complete list of vulnerable versions of OpenSSH including > the 2.x branches? In other words how far back does this issue go? as far as i see buffer.c issue goes back to revision 1.1 (= import from tatu's original ssh). itojun