Re: Bug#923486: CVE-2019-6111 not fixed, file transfer of unwanted files by malicious SSH server still possible

2019-03-10 Thread Ola Lundqvist
Hi again I finally found out why I could not use xstrdup so with that fixed I run the tests again. No crash. My guess is that the crash is some other part of the code and not the newly introduced functions. // Ola On Mon, 11 Mar 2019 at 00:09, Ola Lundqvist wrote: > Hi Mike > > I have had a

Re: Bug#923486: CVE-2019-6111 not fixed, file transfer of unwanted files by malicious SSH server still possible

2019-03-10 Thread Ola Lundqvist
Hi Mike I have had a look at this. First of all I do not think the CVE is completely fixed even with the additional patch. I also do not fully understand how 6111-2.patch is supposed to work. More about this below. Let us give some example commands. [1] scp host:/foobar/a* b [2] scp host:a* b

Re: Bug#923486: CVE-2019-6111 not fixed, file transfer of unwanted files by malicious SSH server still possible

2019-03-08 Thread Mike Gabriel
Hi Colin, hi Debian LTS team, On Fr 01 Mär 2019 13:24:30 CET, Colin Watson wrote: And yes, it looks OK - I'll upload it to unstable shortly. I have prepared a backport of this newly added patch [1] (see #923486 for details) to openssh in Debian jessie LTS, but with that patch backported