2008-01-14
Security fix for insecure use of RandomPool
Following this thread, here is a security fix in the form of an auto-loadable plugin.
Just untar it in your plugin directory (plugin_dir in sshproxy.ini) and you’re safe to go — no need to modify sshproxy.ini to explicitely load it, however you still need to restart the sshproxyd daemon.
The file can be found here. It should be fully compatible with sshproxy 0.5.
If you’re using the source repository, you can update it now, the plugin has been commited.