HomeFreeBSD

Apply upstream fix for CVE-2016-8858:

Description

Apply upstream fix for CVE-2016-8858:

Unregister the KEXINIT handler after message has been received.
Otherwise an unauthenticated peer can repeat the KEXINIT and cause
allocation of up to 128MB -- until the connection is closed.
Reported by shilei-c at 360.cn

Obtained from: OpenBSD

Details

Provenance
delphijAuthored on Nov 2 2016, 6:43 AM
Parents
rGb5a1df4a77c8: Vendor import of OpenSSH 7.2p2.
Branches
Unknown
Tags
Unknown

Event Timeline