Bug 737

Summary: CERT® Advisory CA-2003-26 - any effect on OpenSSH?
Product: Portable OpenSSH Reporter: Steve Moulton <moulton>
Component: sshdAssignee: OpenSSH Bugzilla mailing list <openssh-bugs>
Status: CLOSED INVALID    
Severity: security    
Priority: P2    
Version: -current   
Hardware: All   
OS: All   

Description Steve Moulton 2003-10-09 02:04:44 AEST
Please pardon me if submitting a bug report is not the correct
procedure to address this.

Is OpenSSH affected by the vulnerability in OpenSSL discussed in
http://www.cert.org/advisories/CA-2003-26.html ?  I don't find a reference
to it on the OpenSSH web site.

CERT's only discussion wrt OpenSSH is 
  .  http://www.kb.cert.org/vuls/id/AAMN-5RXR29
  .  an assertion by IBM that it does not affect OpenSSH as they distribute it.
Comment 1 Damien Miller 2003-10-09 07:35:10 AEST
Not significantly. For recent versions of OpenSSH, the OpenSSL ASN.1 code is
used only for loading private keys. It is not used to verify signatures coming
from the network.

For future reference: A bug tracking system is intended for reporting bugs,
please use the mailing list for questions like this.
Comment 2 Damien Miller 2004-04-14 12:24:19 AEST
Mass change of RESOLVED bugs to CLOSED