security vulnerability?

I ran a scan of my Mikrotik’s public IP address with GFI’s LanGuard and it came up with a warning about a bug in SSH versions prior to 3.3 and referenced this bugtrac ID.

Bugtraq ID/URL : 5093
http://www.securityfocus.com/bid/5093

Anyone else seen this?

This was the only warning I got, otherwise Mikrotik seems pretty secure.
The scan did find the ftp port open, is there a reason Mikrotik has to respond with “Mikrotik v2.8.18 ready”? Seems that is giving valuable info to someone doing a port scan.

don’t worry. router os shows incorrect ssh version because we only apply patches to ssh, and therefore the version number doesn’t change to newer. but in actuality the ssh is the latest one.