FreeBSD Security Advisory FreeBSD-SA-03:08.realpath

Jacques A. Vidrine nectar at FreeBSD.org
Mon Aug 4 14:32:06 PDT 2003


On Mon, Aug 04, 2003 at 11:17:18PM +0200, Troels Holm wrote:
> Jacques A. Vidrine wrote:
> >> Does the openssh file need to be patched too?
> >
> > No, it is not used.
> 
> But it states in the advisory that "sftp-server" is negatively
> impacted....And its a part of OpenSSH.
> Or did I get you wrong?

The realpath.c that is distributed with OpenSSH-portable and found in
our CVS tree as /usr/src/crypto/openssh/openbsd-compat/realpath.c is
not used.

Cheers,
-- 
Jacques Vidrine   . NTT/Verio SME      . FreeBSD UNIX       . Heimdal
nectar at celabo.org . jvidrine at verio.net . nectar at freebsd.org . nectar at kth.se


More information about the freebsd-security mailing list