What's the point on this for us, CentOS users ?
http://www.redhat.com/security/data/openssh-blacklist.html
Regards, kfx
On Fri, Aug 22, 2008 at 05:43:08PM +0200, kfx wrote:
What's the point on this for us, CentOS users ?
That will only test for compiled RPMS of certain OpenSSH packages.
Those RPMS have been signed by the PGP key, so either the key server or the build server were compromised (possibly they are the same, I don't know).
I'd do a detailed review of the SRPMS and patches during this period...
Rui