OpenSSH 3.1

ME dugan at passwall.com
Thu Mar 14 13:13:15 PST 2002


0.9.6 or later on all systems that have the new openssh3.1p1
installed. I think one of the readme's in the openssh install stated it
needed openssl

If you make/install your own openssl, you may wish to install it under
/usr/local and then explicitly tell openssh's configure script 
"--with-ssl-dir=/usr/local/ssl"

While you are at it, make sure you can get a patched zlib for openssh's
lib inclusion. (Just because nobody has published an exploit for openssh
with zlib, and most evidence that has come to light suggests it is not
presently possible with the present openssh, it was still found to be a
limited DoS as it kills the session. A png file was discussed that could
trigger the zlib problem on bugrtaq.)

-ME

-----BEGIN GEEK CODE BLOCK-----
Version: 3.12
GCS/CM$/IT$/LS$/S/O$ !d--(++) !s !a+++(-----) C++$(++++) U++++$(+$) P+$>+++ 
L+++$(++) E W+++$(+) N+ o K w+$>++>+++ O-@ M+$ V-$>- !PS !PE Y+ !PGP
t at -(++) 5+@ X@ R- tv- b++ DI+++ D+ G--@ e+>++>++++ h(++)>+ r*>? z?
------END GEEK CODE BLOCK------
decode: http://www.ebb.org/ungeek/ about: http://www.geekcode.com/geek.html

On Thu, 14 Mar 2002, Warren Raquel wrote:
> What version of openssl are you running. I have 0.9.5a running and I'm going
> to upgrade it to 6c.
> ----- Original Message -----
> From: "ME" <dugan at passwall.com>
> To: <talk at nblug.org>
> Sent: Thursday, March 14, 2002 12:43 PM
> Subject: Re: OpenSSH 3.1
> 
> 
> > I use Debian, not RedHat and did not have a problem with this.
> >
> > What kind of problem is it having with cipher.o ? missing libs? Complaints
> > about something missing? I assume you have run ./configure with the
> > flags/args appropriate for your system (MD5 password, shadow
> > disabled/enabled, PAM etc)
> >
> > -ME
> >
> > -----BEGIN GEEK CODE BLOCK-----
> > Version: 3.12
> > GCS/CM$/IT$/LS$/S/O$ !d--(++) !s !a+++(-----) C++$(++++) U++++$(+$)
> P+$>+++
> > L+++$(++) E W+++$(+) N+ o K w+$>++>+++ O-@ M+$ V-$>- !PS !PE Y+ !PGP
> > t at -(++) 5+@ X@ R- tv- b++ DI+++ D+ G--@ e+>++>++++ h(++)>+ r*>? z?
> > ------END GEEK CODE BLOCK------
> > decode: http://www.ebb.org/ungeek/ about:
> http://www.geekcode.com/geek.html
> >      Systems Department Operating Systems Analyst for the SSU Library
> >
> > On Thu, 14 Mar 2002, Warren Raquel wrote:
> > > Ok, I'm getting crap trying to rebuild the openssh rpm (3.1p1) in
> > > RedHat 6.2 so I went to get the source. Well, I run the same problem
> > > from the source. It keeps getting stuck trying to compile cipher.o.
> > > Anyone else run into this and how do I get around it?
> >
> >
> 



More information about the talk mailing list