OpenSSL vulnerability...
Markus Friedl
markus at openbsd.org
Sun Oct 5 01:00:35 EST 2003
On Thu, Oct 02, 2003 at 04:32:56PM -0400, Asif Iqbal wrote:
> On Tue, 30 Sep 2003, Markus Friedl wrote:
>
> > On Tue, Sep 30, 2003 at 12:06:30PM -0500, hayward at slothmud.org wrote:
> > > Does OpenSSH use OpenSSL in a way in which it would be vulnerable to the
> > > OpenSSL vulnerabilities announced today? Namely the ASN.1 parsing
> > > problem and the malformed key bugs?
> >
> > no, we avoid the OpenSSL ASN.1 code for signature verification
> > and we don't support x509.
> >
> > only reading of _private_ keys triggers the ASN.1 code
> > in OpenSSH.
>
> Does this statement encompass login with RSA keys ?
the 1st: yes
2nd: sshd reads _private_ keys only when reading the hostkey.
More information about the openssh-unix-dev
mailing list