Upgrading sshd?

Lowell Gilbert freebsd-questions-local at be-well.no-ip.com
Tue Sep 16 12:26:17 PDT 2003


Johan Paul <mailing-lists at johanpaul.com> writes:

> Refering to the latest sshd vurnability
> (http://slashdot.org/articles/03/09/16/1327248.shtml?tid=126&tid=172)
> I was thinking of upgradeing my sshd as well. So I cvsup'ed my system
> (FBSD 4.8) and there seems to be a updated file for sshd. But how do I
> upgrade sshd safly since when I type 'pkg_info |grep ssh' it return no
> packages. I guess sshd is included somehow by the default install (??)
> but how can I now upgrade it? I was thinking of portupgrade, but it
> needs a package to upgrade...

Right.  openssh is part of the base system, and not normally installed
as a package.  There is a security advisory newly out on the usual
FreeBSD mailing lists, and it gives instructions on fixing just this
one problem, but it's probably better to update the whole system when
you get a chance.  [Note that this vulnerability does *not* give
attackers an opportunity to run their code on your system.]


More information about the freebsd-questions mailing list