▲ | rollcat 5 days ago | |
I think in case of any security-critical project it's important to evaluate the track record objectively: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=OpenSSH It's true that there are 5 advisories so far in this year alone, but let's consider the actual impact:
OpenBSD enables sshd(8) in the default install, and has so far had two RCEs in 30 years. Now, not everyone runs OpenBSD, but I'd personally throw the stones at e.g. Debian (see CVE-2008-0166). |