Return-Path: <mhpower@MIT.EDU>
Received: from MIT.EDU by po12.mit.edu (8.9.2/4.7) id SAA10906; Thu, 8 Feb 2001 18:22:34 -0500 (EST)
From: <mhpower@MIT.EDU>
Received: from customer-care.infrastructure.org by MIT.EDU with SMTP id AA22982; Thu, 8 Feb 01 18:20:42 EST
Received: (qmail 66415 invoked by uid 7783); 8 Feb 2001 23:22:16 -0000
Message-Id: <20010208232216.66414.qmail@customer-care.infrastructure.org>
Date: Thu, 8 Feb 2001 18:22:16 -0500
To: sec-dn@akamai.com
Cc: security-internal@MIT.EDU
Subject: another sshd remote-root vulnerability (different from yesterday's)
X-Evolution: 00000084-0000

There's another opportunity for remote-root exploit of sshd, different
from the one published yesterday that involved determining a session
key by making about a million connections to an sshd. This one is a
"make one connection to the sshd" type of remote-root vulnerability.

See: http://razor.bindview.com/publish/advisories/adv_ssh1crc.html
     http://marc.theaimsgroup.com/?l=openssh-unix-dev&m=98167297313258&w=2

Matt Power
mhpower@mit.edu
