Secure Computing Corporation Information for VU#978316
Vulnerability in OpenSSH daemon (sshd)
- Vendor Information Help Date Notified: 06 Jun 2003
- Statement Date:
- Date Updated: 16 Jun 2003
This vulnerability relates to OpenSSH's internal mechanism for restricting connections based on the source address. While Sidewinder uses OpenSSH, source address restrictions are handled by the Sidewinder policy engine. Since OpenSSH's internal mechanism is not used, Sidewinder is not affected by this vulnerability. As a matter of policy, the updated SSH code will be included in a future patch.
The Gauntlet firewall does not include an SSH daemon, and is thus not affected by this vulnerability.
The vendor has not provided us with any further information regarding this vulnerability.
The CERT/CC has no additional comments at this time.