zie http://www.pine.nl/advisories/pine-cert-20020301.html :
Advisory ID : PINE-CERT-20020301
Authors : Joost Pol
Issue date : 2002-03-07
Application : OpenSSH
Version(s) : All versions between 2.0 and 3.0.2
Platforms : multiple
Vendor informed : 20020304
Availability : http://www.pine.nl/advisories/pine-cert-20020301.asc
Revision : 1.1
------------------------------------------------------------------------
Synopsis
A bug exists in the channel code of OpenSSH versions 2.0 - 3.0.2
Users with an existing user account can abuse this bug to
gain root privileges. A malicious ssh server could also use
this bug to exploit a connecting vulnerable client.
Impact
HIGH: Existing users will gain root privileges.
Description
Simple off by one error. Patch included.
Solution
The OpenSSH project will shortly release version 3.1.
Upgrading to this version is highly recommended.
This version will be made available at www.openssh.com
The FreeBSD port of OpenSSH has been updated to reflect the
patches as supplied in this document.
OpenSSH CVS has been updated, see
OpenBSD cvs entry for channels.c
Or apply the patch as provided by PINE Internet:
http://www.pine.nl/advisories/pine-cert-20020301.patch
Klaar voor een nieuwe uitdaging.