According to the Internet Storm Center, there seems to be a SSH zero-day exploit out there.
There is some proof of concept code in here and some reference:
- http://secer.org/hacktools/0day-openssh-remote-exploit.html
- http://isc.sans.org/diary.html?storyid=6742
This seems to be a serious issue, so every Linux/Unix system administrator should be careful.
How do we protect ourselves if this issue is not patched on time? Or how do you handle zero-day exploits in general?
*I will post my suggestion in the replies.