Path to this page:
Subject: CVS commit: pkgsrc/security/lsh
From: Lubomir Sedlacik
Date: 2006-04-06 01:59:33
Message id: 20060405235933.93C412DA27@cvs.netbsd.org
Log Message:
Backport fix for CVE-2006-0353 from lsh2:
"unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related
to the randomness generator, which allows local users to cause a denial
of service by truncating the seed file, which prevents the server from
starting, or obtain sensitive seed information that could be used to
crack keys."
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0353
Files: