From owner-freebsd-security Fri Mar 16 10:33:26 2001 Delivered-To: freebsd-security@freebsd.org Received: from ringworld.nanolink.com (ringworld.nanolink.com [195.24.48.13]) by hub.freebsd.org (Postfix) with SMTP id 5EC0237B71A for ; Fri, 16 Mar 2001 10:33:21 -0800 (PST) (envelope-from roam@orbitel.bg) Received: (qmail 8263 invoked by uid 1000); 16 Mar 2001 18:32:38 -0000 Date: Fri, 16 Mar 2001 20:32:38 +0200 From: Peter Pentchev To: James Snow Cc: Kris Kennaway , Brooks Davis , Alex Popa , security@FreeBSD.ORG Subject: Re: 4.3-BETA, sshd.core found in root directory. Message-ID: <20010316203238.A8245@ringworld.oblivion.bg> Mail-Followup-To: James Snow , Kris Kennaway , Brooks Davis , Alex Popa , security@FreeBSD.ORG References: <20010313004813.A78221@ldc.ro> <20010312145754.A489@Odin.AC.HMC.Edu> <20010312152215.A94640@mollari.cthul.hu> <20010316125532.A65814@teardrop.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: <20010316125532.A65814@teardrop.org>; from snow@teardrop.org on Fri, Mar 16, 2001 at 12:55:32PM -0500 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org On Fri, Mar 16, 2001 at 12:55:32PM -0500, James Snow wrote: > > The problematic code is in src/crypto/openssh/auth2.c in > input_userauth_request: I believe Brian Feldman, the maintainer of OpenSSH in FreeBSD, committed a similar fix earlier today :) G'luck, Peter -- When you are not looking at it, this sentence is in Spanish. To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message