[Full-Disclosure] OpenSSH exploit

Adam Dyga adeon at o2.pl
Tue Sep 16 21:53:25 BST 2003


| Is there a complete list of vulnerable versions of OpenSSH including
| the 2.x branches?  In other words how far back does this issue go?

Just compare buffer_append_space() function in buffer.c in all versions you 
are interested in...

-- 
Greets
adeon




Full-Disclosure is hosted and sponsored by Secunia.