Tuesday, November 07, 2006

New OpenSSH 4.5/4.5p1 released Nov 7, 2006

OpenSSH is a FREE version of the SSH connectivity tools that technical users of the Internet rely on. Users of telnet, rlogin, and ftp may not realize that their password is transmitted across the Internet unencrypted, but it is. OpenSSH encrypts all traffic (including passwords) to effectively eliminate eavesdropping, connection hijacking, and other attacks. Additionally, OpenSSH provides secure tunneling capabilities and several authentication methods, and supports all SSH protocol versions.
Changes since OpenSSH 4.4:
This is a bugfix only release. No new features have been added.
Security bugs resolved in this release:
  • Fix a bug in the sshd privilege separation monitor that weakened its verification of successful authentication. This bug is not known to be exploitable in the absence of additional vulnerabilities. This release includes the following non-security fixes.
  • Several compilation fixes for portable OpenSSH.
  • Fixes to Solaris SMF/process contract support (bugzilla #1255)Thanks to everyone who has contributed patches, reported bugs andtested releases.
Source : http://www.openssh.com/

No comments:

Security News