[Midnightbsd-cvs] src: crypto/openssh: Enable the new GLOB_LIMIT flag to fix a security

laffer1 at midnightbsd.org laffer1 at midnightbsd.org
Fri Oct 8 12:37:52 EDT 2010


Log Message:
-----------
Enable the new GLOB_LIMIT flag to fix a security vulnerability that is remotely exploitable with sftp daemon.
This enables the patch to libc/gen/glob.c

Modified Files:
--------------
    src/crypto/openssh:
        sftp-glob.c (r1.1.1.2 -> r1.2)
        (http://cvsweb.midnightbsd.org/src/crypto/openssh/sftp-glob.c?r1=1.1.1.2&r2=1.2)
        sftp.c (r1.6 -> r1.7)
        (http://cvsweb.midnightbsd.org/src/crypto/openssh/sftp.c?r1=1.6&r2=1.7)


More information about the Midnightbsd-cvs mailing list