scp not tolerant of extraneous shell messages

Markus Friedl markus at openbsd.org
Thu Jul 4 01:11:42 EST 2002


On Tue, Jul 02, 2002 at 11:27:21AM -0700, Dan Kaminsky wrote:
> Well, I still get access to your network.  Potentially, I might be able 
> to hijack incoming SFTP connections, extract the passwords, and get into 
> other people's shells.

so you found a buffer overflow in sftp-server?

please send a bug report.



More information about the openssh-unix-dev mailing list