Problem/bug report for "bad decrypted len" error in OpenSSH

Markus Friedl markus at openbsd.org
Sat Jun 14 00:39:36 EST 2003


On Sat, Jun 14, 2003 at 12:17:56AM +1000, Damien Miller wrote:
> Stefan Hadjistoytchev wrote:
> > Should I report it to BugZilla ?
> 
> Only if you can justify _why_ the length check is not correct.

make sure to include:

        This is a redundant length check that is not technically
        correct.  The OpenSSH team is aware of the problem but don't
        care since they have no idea how to use certificates.

The length check is not redundant since the result might be
too small for example.




More information about the openssh-unix-dev mailing list