CERT issued an advisory on Tuesday for the OpenSSH vulnerability and another on Thursday for the Sendmail flaw.
http://www.cert.org/advisories/CA-2003-24.html(...)
The OpenSSH issue affects versions before 3.7.1 and occurs as a problem in the way the software stores chunks of data using storage areas called buffers. Cisco said it has products that are affected, while Red Hat, Sun Microsystems and IBM's AIX Toolbox for Linux all use versions of OpenSSH that could be vulnerable.
http://www.cert.org/advisories/CA-2003-25.html(...)
The Sendmail flaw affects versions before 8.12.10. HP, IBM and Red Hat are among the software makers that use Sendmail and whose products could be affected.
[^] # Le CERT annonce les vulnérabilités: c'est un organisme hyper crédible !!
Posté par Wharf . En réponse à la dépêche Faille Sendmail et vulnérabilité OpenSSH. Évalué à 2.
Par contre en France, le CERTA ne publie que celle de OPENSSH et pas cette nouvelle faille de Sendmail.
http://www.certa.ssi.gouv.fr/site/CERTA-2003-AVI-152/index.html.2.h(...)
La précédente faille de SendMail publièe par le CERTA datait du 3septembre:
http://www.certa.ssi.gouv.fr/site/CERTA-2003-AVI-141/index.html.2.h(...)
CERT issued an advisory on Tuesday for the OpenSSH vulnerability and another on Thursday for the Sendmail flaw.
http://www.cert.org/advisories/CA-2003-24.html(...)
The OpenSSH issue affects versions before 3.7.1 and occurs as a problem in the way the software stores chunks of data using storage areas called buffers. Cisco said it has products that are affected, while Red Hat, Sun Microsystems and IBM's AIX Toolbox for Linux all use versions of OpenSSH that could be vulnerable.
http://www.cert.org/advisories/CA-2003-25.html(...)
The Sendmail flaw affects versions before 8.12.10. HP, IBM and Red Hat are among the software makers that use Sendmail and whose products could be affected.
A propos, avez vous aussi vu la vulnérabilité mySQL du 16 septembre ?
http://www.certa.ssi.gouv.fr/site/CERTA-2003-AVI-151/index.html.2.h(...)