Skip to content

Commit

Permalink
HBSD: temporary fix / workaround for OpenSSH's CVE-2016-0777
Browse files Browse the repository at this point in the history
List:       openbsd-tech
Subject:    Important SSH patch coming soon
From:       Theo de Raadt <deraadt () openbsd ! org>
Date:       2016-01-14 14:05:36
Message-ID: 29041.1452780336 () cvs ! openbsd ! org
[Download message RAW]

Important SSH patch coming soon.  For now, every on all operating
systems, please do the following:

Add undocumented "UseRoaming no" to ssh_config or use "-oUseRoaming=no"
to prevent upcoming #openssh client bug CVE-2016-0777. More later.

https://www.marc.info/?l=openbsd-tech&m=145278077820529&w=2
http://undeadly.org/cgi?action=article&sid=20160114142733

Thanks-for-the-info: Hunger <hunger+hbsd@hunger.hu>
Signed-off-by: Oliver Pinter <oliver.pinter@hardenedbsd.org>
  • Loading branch information
opntr committed Jan 14, 2016
1 parent 4c9501e commit 831e468
Showing 1 changed file with 1 addition and 0 deletions.
1 change: 1 addition & 0 deletions crypto/openssh/ssh_config
Expand Up @@ -49,3 +49,4 @@
# RekeyLimit 1G 1h
# VerifyHostKeyDNS yes
# VersionAddendum FreeBSD-20140420
UseRoaming no

0 comments on commit 831e468

Please sign in to comment.