OpenSSH Security bug: port forwarding

Pekka Savola pekkas at netcore.fi
Tue Nov 21 03:17:43 EST 2000


On Mon, 20 Nov 2000, Peter Berger wrote:
> Yes, I had GatewayPorts set to 'no' -- this is clearly not a bug in ssh,
> but in the version of Linux I'm using.  When I debugged, ssh was binding
> to 0.0.0.0.
>
> Oh well.  We shouldn't be using Linux as a firewall anyway.

Try upgrading the kernel and/or glibc; that should be done for stability,
security and speed reasons anyway.

getaddrinfo as defined in fake-getaddrinfo.c is failing for you, probably.

-- 
Pekka Savola                 "Tell me of difficulties surmounted,
Pekka.Savola at netcore.fi      not those you stumble over and fall"






More information about the openssh-unix-dev mailing list