Bug#729029: openssh: Memory corruption in AES-GCM support

2013-11-09 Thread Colin Watson
Control: tag -1 pending On Fri, Nov 08, 2013 at 06:38:17AM +0100, Moritz Muehlenhoff wrote: > Please see http://www.openssh.com/txt/gcmrekey.adv I've merged 6.4p1 into my development branch. I'm hoping for #722970 to be fixed this weekend so that I can just upload that directly; otherwise I gues

Bug#729029: openssh: Memory corruption in AES-GCM support

2013-11-07 Thread Moritz Muehlenhoff
Package: openssh Severity: grave Tags: security Justification: user security hole Please see http://www.openssh.com/txt/gcmrekey.adv No CVE ID has been assigned yet. AES-GCM support was introduced in 6.2, so oldstable and stable should be fine (from http://www.openssh.com/txt/release-6.2): | *