HomeFreeBSD

Apply upstream fix for CVE-2016-10009 and CVE-2016-10010:

Description

Apply upstream fix for CVE-2016-10009 and CVE-2016-10010:

add a whitelist of paths from which ssh-agent will load (via
ssh-pkcs11-helper) a PKCS#11 module; ok markus@

disable Unix-domain socket forwarding when privsep is disabled

(Note that this is a backport of upstream fixes, and this commit
is mainly to ease future imports).

Obtained from: OpenBSD

Details

Provenance
delphijAuthored on Jan 11 2017, 5:42 AM
Parents
rG642a1c3843c9: Apply upstream fix for CVE-2016-8858:
Branches
Unknown
Tags
Unknown

Event Timeline