FreeBSD Security Advisory FreeBSD-SA-03:08.realpath
Jacques A. Vidrine
nectar at FreeBSD.org
Mon Aug 4 14:32:06 PDT 2003
On Mon, Aug 04, 2003 at 11:17:18PM +0200, Troels Holm wrote:
> Jacques A. Vidrine wrote:
> >> Does the openssh file need to be patched too?
> >
> > No, it is not used.
>
> But it states in the advisory that "sftp-server" is negatively
> impacted....And its a part of OpenSSH.
> Or did I get you wrong?
The realpath.c that is distributed with OpenSSH-portable and found in
our CVS tree as /usr/src/crypto/openssh/openbsd-compat/realpath.c is
not used.
Cheers,
--
Jacques Vidrine . NTT/Verio SME . FreeBSD UNIX . Heimdal
nectar at celabo.org . jvidrine at verio.net . nectar at freebsd.org . nectar at kth.se
More information about the freebsd-security
mailing list