[sans+ZZ86840642882145134@sans.org: Security Alert Consensus #050]

Michael J McCafferty mike at m5computersecurity.com
Fri Dec 20 14:43:45 PST 2002


         I am reading the neohapsis web pages right now, and one says:

PuTTY 0.53b addresses vulnerabilities discovered by SSHredder.

and on the other page............

    o PuTTY SSH client for Windows
         v0.53 and earlier (v0.53b not affected)


What did I miss ?


At 02:17 PM 12/20/2002 -0800, you wrote:
> > OK, I use OpenSSH on my server and laptop, and occasionally putty on my
> > office WS. That's putty for access only. Am I vulnerable?
>
>Apparently yes.  Putty doesn't have a patch out yet.  Actually,
>the site doesn't mention the problem at all, best i can tell.
>
>-Darrel

**************************************************
Michael J. McCafferty
M5 Computer Security
858-576-7325 Voice
PGP Key ID:   0x2206347F
http://www.m5computersecurity.com
**************************************************
--- "If you build it, they will hack !" ---




More information about the KPLUG-List mailing list