Re: [OE-core] [OE-Core] [Fido] [PATCH] openssh: Backport CVE-2015-5600 fix

2015-11-30 Thread Haris Okanovic
On 11/05/2015 04:00 PM, Joshua Lock wrote: Thanks, I've pushed this change to my joshuagl/fido-next branch of openembedded-core-contrib and am testing it now. You can find instructions on testing the vulnerability at the following URL. I forgot to include it in the change description.

Re: [OE-core] [OE-Core] [Fido] [PATCH] openssh: Backport CVE-2015-5600 fix

2015-11-05 Thread Joshua Lock
On 30/10/15 20:12, Haris Okanovic wrote: only query each keyboard-interactive device once per authentication request regardless of how many times it is listed Source: http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth2-chall.c?f=h#rev1.43

[OE-core] [OE-Core] [Fido] [PATCH] openssh: Backport CVE-2015-5600 fix

2015-10-30 Thread Haris Okanovic
only query each keyboard-interactive device once per authentication request regardless of how many times it is listed Source: http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth2-chall.c?f=h#rev1.43