[openssh-commits] CVS: fuyu.mindrot.org: openssh

Damien Miller djm at fuyu.mindrot.org
Wed Jul 9 20:54:05 EST 2008


CVSROOT:        /var/cvs
Module name:    openssh
Changes by:     djm at fuyu.mindrot.org 08/07/09 20:54:05

Modified files:
    .               : ChangeLog auth1.c

Log message:
 - (djm) [auth1.c] Fix format string vulnerability in protocol 1 PAM
   account check failure path. The vulnerable format buffer is supplied
   from PAM and should not contain attacker-supplied data.

Diff commands:
cvs -nQq rdiff -u -r1.5066 -r1.5067 openssh/ChangeLog
cvs -nQq rdiff -u -r1.123 -r1.124 openssh/auth1.c

CVSWeb:
http://cvsweb.mindrot.org/index.cgi/openssh/ChangeLog?r1=1.5066;r2=1.5067
http://cvsweb.mindrot.org/index.cgi/openssh/auth1.c?r1=1.123;r2=1.124

Please note that there may be a delay before commits are available
on the public CVSWeb site.


More information about the openssh-commits mailing list