Re: Need Help to Fix CVE-2008-1483, CVE-2008-5161, CVE-2015-5600 and CVE-2015-6565

[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

 



On Mon, 14 Mar 2016, abhi dhiman wrote:

> Hi All,
> 
> Please direct me to the code changes for above vulnerabilities.
> We don't have a vendor but we use Openssh in our software. So can't upgrade
> it right now.

OpenSSH is maintained by a small team who only have the resources to
support the current version. If you need to generate cherry-pick
patches then you'll either need to do it yourself or find a competent
developer to do it for you.

Finding them yourself isn't too hard: checkout the version containing
the fix from git and look at the commit log. Security vulnerabilities
usually preciptate a release quite quickly, so it will like be one of
the last commits in the log. Do be careful: people have caused problem
by mis-applying cherry-pick patches inappropriately before. It's
much better just to use the latest version.

-d
_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@xxxxxxxxxxx
https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev



[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux