Plaintext recovery attack in SSH, discovered by CPNI?

Eygene Ryabinkin rea-fbsd at codelabs.ru
Fri Nov 21 05:13:49 PST 2008


Damien, good day.

Fri, Nov 21, 2008 at 10:10:32PM +1100, Damien Miller wrote:
> see http://www.openssh.com/txt/cbc.adv

Thanks!  Is there some secret place that links to this (and other)
advisory or I should just poll http://openssh.org/txt/? ;))
-- 
Eygene
 _                ___       _.--.   #
 \`.|\..----...-'`   `-._.-'_.-'`   #  Remember that it is hard
 /  ' `         ,       __.--'      #  to read the on-line manual   
 )/' _/     \   `-_,   /            #  while single-stepping the kernel.
 `-'" `"\_  ,_.-;_.-\_ ',  fsc/as   #
     _.-'_./   {_.'   ; /           #    -- FreeBSD Developers handbook 
    {_.-``-'         {_/            #
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 195 bytes
Desc: not available
Url : http://lists.freebsd.org/pipermail/freebsd-security/attachments/20081121/33f0a31a/attachment.pgp


More information about the freebsd-security mailing list