From owner-freebsd-security@FreeBSD.ORG Fri Nov 21 13:26:32 2008 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id BABF1106564A for ; Fri, 21 Nov 2008 13:26:32 +0000 (UTC) (envelope-from mailnull@mips.inka.de) Received: from mail-in-16.arcor-online.net (mail-in-16.arcor-online.net [151.189.21.56]) by mx1.freebsd.org (Postfix) with ESMTP id 717998FC08 for ; Fri, 21 Nov 2008 13:26:32 +0000 (UTC) (envelope-from mailnull@mips.inka.de) Received: from mail-in-16-z2.arcor-online.net (mail-in-16-z2.arcor-online.net [151.189.8.33]) by mail-in-16.arcor-online.net (Postfix) with ESMTP id 836ED1F7352 for ; Fri, 21 Nov 2008 13:53:38 +0100 (CET) Received: from mail-in-14.arcor-online.net (mail-in-14.arcor-online.net [151.189.21.54]) by mail-in-16-z2.arcor-online.net (Postfix) with ESMTP id 5FC57254253 for ; Fri, 21 Nov 2008 13:53:38 +0100 (CET) Received: from lorvorc.mips.inka.de (dslb-092-075-214-094.pools.arcor-ip.net [92.75.214.94]) by mail-in-14.arcor-online.net (Postfix) with ESMTP id F1A55187DEE for ; Fri, 21 Nov 2008 13:53:37 +0100 (CET) Received: from lorvorc.mips.inka.de (localhost [127.0.0.1]) by lorvorc.mips.inka.de (8.14.3/8.14.3) with ESMTP id mALCrYqM041185 for ; Fri, 21 Nov 2008 13:53:34 +0100 (CET) (envelope-from mailnull@lorvorc.mips.inka.de) Received: (from mailnull@localhost) by lorvorc.mips.inka.de (8.14.3/8.14.3/Submit) id mALCrYdH041184 for freebsd-security@freebsd.org; Fri, 21 Nov 2008 13:53:34 +0100 (CET) (envelope-from mailnull) From: naddy@mips.inka.de (Christian Weisgerber) Date: Fri, 21 Nov 2008 12:53:34 +0000 (UTC) Message-ID: References: <6p2tlso0g3Xi5suHfErE3rcPs54@Mr6N54GlMnGhD+RQ1Yhx+24IxLk> Originator: naddy@mips.inka.de (Christian Weisgerber) To: freebsd-security@freebsd.org X-Virus-Scanned: ClamAV 0.94.1/8658/Fri Nov 21 11:54:22 2008 on mail-in-14.arcor-online.net X-Virus-Status: Clean Subject: Re: Plaintext recovery attack in SSH, discovered by CPNI? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 21 Nov 2008 13:26:32 -0000 Eygene Ryabinkin wrote: > So, it is interesting what OpenSSH developers can tell about this: > I had seen no words about this at http://openssh.org/security.html > and relese notes, so if you can -- please, comment on this. http://www.openssh.com/txt/cbc.adv -- Christian "naddy" Weisgerber naddy@mips.inka.de