X-Recipient: archive-cygwin AT delorie DOT com X-Spam-Check-By: sourceware.org Date: Thu, 26 Feb 2009 11:36:43 +0100 From: Corinna Vinschen To: cygwin AT cygwin DOT com Subject: Re: [ANNOUNCEMENT] [1.7] Updated: OpenSSH-5.2p1-1 Message-ID: <20090226103643.GV18319@calimero.vinschen.de> Reply-To: cygwin AT cygwin DOT com Mail-Followup-To: cygwin AT cygwin DOT com References: <17f020130902250712h426d233bofa68d3504689702d AT mail DOT gmail DOT com> <20090226091207 DOT GT18319 AT calimero DOT vinschen DOT de> <17f020130902260139h29e57c5area85ef624dc5377e AT mail DOT gmail DOT com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <17f020130902260139h29e57c5area85ef624dc5377e@mail.gmail.com> User-Agent: Mutt/1.5.19 (2009-02-20) Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm Precedence: bulk List-Id: List-Unsubscribe: List-Subscribe: List-Archive: List-Post: List-Help: , Sender: cygwin-owner AT cygwin DOT com Mail-Followup-To: cygwin AT cygwin DOT com Delivered-To: mailing list cygwin AT cygwin DOT com On Feb 26 10:39, Frank Fesevur wrote: > 2009/2/26 Corinna Vinschen: > > On Feb 25 16:12, Frank Fesevur wrote: > >> Since this is a security fix, will there be a 1.5 update as well? > > > > Well, actually I have no intention to update 1.5.x packages anymore. > > I understand you want us to start using 1.7, but in the announcement > of 1.7.0-41 you write in capitals: > > ==================================================================== > THIS IS STILL A TEST RELEASE. DON'T USE IN PRODUCTION ENVIRONMENTS. > ==================================================================== > > So I didn't install 1.7 on our server, but apparently now it has a > security problem. You can workaround the problem in 5.1p1 by specifying the "Ciphers" option in sshd_config, like this: Ciphers aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,arcfour This disables thr CBC ciphers which are mentioned in the advisory. Corinna -- Corinna Vinschen Please, send mails regarding Cygwin to Cygwin Project Co-Leader cygwin AT cygwin DOT com Red Hat -- Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple Problem reports: http://cygwin.com/problems.html Documentation: http://cygwin.com/docs.html FAQ: http://cygwin.com/faq/