[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: OpenSSH Security Advisory: Trojaned Distribution Files



On Thu, Aug 01, 2002 at 01:00:30PM -0400, Brian Szymanski wrote:
> Just to be nice and sparkling clear on this issue - this only affected the
> portable openssh package, correct? Is it true that the non-portable (ie,
> OpenBSD specific) package was NOT trojaned at any time (that anyone knows
> about, anyway)? Thanks in advance.

I don't know why I'm contributing to this frenzy, but according to

http://docs.freebsd.org/cgi/getmsg.cgi?fetch=496780+0+current/freebsd-security
> The following changes occured to ftp.openssh.com:
>
> Old size -> new size name
>
> 398595 ->     401466 openssh-3.4.tgz
> 822567 ->     825630 portable/openssh-3.2.2p1.tar.gz
> 837668 ->     840574 portable/openssh-3.4p1.tar.gz

-andy