OpenSSH Releases Version 5.0
os2man lets us know that OpenSSH version 5.0 has been released. The mirrors are linked from the top page. "OpenSSH (OpenBSD Secure Shell) is a set of computer programs providing encrypted communication sessions over a computer network using the ssh protocol. It was created as an open source alternative to the proprietary Secure Shell software suite offered by SSH Communications Security. OpenSSH is available for almost any Operating System."
Nice how the release note is used to complain about Debian maintainers specifically.
Security:
* CVE-2008-1483: Avoid possible hijacking of X11-forwarded connections
by refusing to listen on a port unless all address families bind
successfully.
Uhm, so they can fix the problem before it becomes known to the cracking community?
Jeremy
Since the private list members are the OpenSSH maintainers, not trusting them at this point is a bit split-brain. It's like asking someone to hold your wallet and refusing to give them your coat because you don't trust them to keep it safe. In for a penny ...
The little guy just ain't getting it, is he?
Does anyone know if the chroot feature has been included (previously mentioned on slashdot)? Or is this just an upgrade for the security fix?
No, it's perfectly rational.
In one case, you're trusting the OpenSSH maintainers, as a group, not to put deliberate backdoors into the code that everyone will see. You're trusting them to behave well when the risk of being discovered is quite high. You also have the option of auditing the code yourself, so you don't even have to give them your complete trust.
In the other case, you are trusting each individual OpenSSH maintainer not to use his newly-acquired knowledge against specific targets when the risk of being discovered is quite low.
http://outcampaign.org/