Please pardon me if submitting a bug report is not the correct procedure to address this. Is OpenSSH affected by the vulnerability in OpenSSL discussed in http://www.cert.org/advisories/CA-2003-26.html ? I don't find a reference to it on the OpenSSH web site. CERT's only discussion wrt OpenSSH is . http://www.kb.cert.org/vuls/id/AAMN-5RXR29 . an assertion by IBM that it does not affect OpenSSH as they distribute it.
Not significantly. For recent versions of OpenSSH, the OpenSSL ASN.1 code is used only for loading private keys. It is not used to verify signatures coming from the network. For future reference: A bug tracking system is intended for reporting bugs, please use the mailing list for questions like this.
Mass change of RESOLVED bugs to CLOSED