Bug 737 - CERT® Advisory CA-2003-26 - any effect on OpenSSH?
Summary: CERT® Advisory CA-2003-26 - any effect on OpenSSH?
Status: CLOSED INVALID
Alias: None
Product: Portable OpenSSH
Classification: Unclassified
Component: sshd (show other bugs)
Version: -current
Hardware: All All
: P2 security
Assignee: OpenSSH Bugzilla mailing list
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2003-10-09 02:04 AEST by Steve Moulton
Modified: 2004-04-14 12:24 AEST (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Steve Moulton 2003-10-09 02:04:44 AEST
Please pardon me if submitting a bug report is not the correct
procedure to address this.

Is OpenSSH affected by the vulnerability in OpenSSL discussed in
http://www.cert.org/advisories/CA-2003-26.html ?  I don't find a reference
to it on the OpenSSH web site.

CERT's only discussion wrt OpenSSH is 
  .  http://www.kb.cert.org/vuls/id/AAMN-5RXR29
  .  an assertion by IBM that it does not affect OpenSSH as they distribute it.
Comment 1 Damien Miller 2003-10-09 07:35:10 AEST
Not significantly. For recent versions of OpenSSH, the OpenSSL ASN.1 code is
used only for loading private keys. It is not used to verify signatures coming
from the network.

For future reference: A bug tracking system is intended for reporting bugs,
please use the mailing list for questions like this.
Comment 2 Damien Miller 2004-04-14 12:24:19 AEST
Mass change of RESOLVED bugs to CLOSED