Subject: OpenSSH package vulnerability
To: None <tech-pkg@netbsd.org>
From: Lange rote stumpfe <rabbitbait@imtarget.cotse.net>
List: tech-pkg
Date: 09/21/2005 12:03:30
Hey there noble package masters,

Easy for me to say, but is moving the OpenSSH package ro 4.2 or later much
of a priority, seeng as how it has a priv escalation vulnerability?

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2798

I've never had to define ALLOW_VULNERABLE_PACKAGES before, and it makes me
a bit uneasy

Lange

PS Thanks, nonetheless for your labours. I can't express my apperciation
in words (really, see my misspellings!) but it means a lot to lots of us.