[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [PATCH] Set correct state after sending INFO_REQUEST (Kbd Interactive)


Hi Andreas,


I have sent the Certificate of Origin already, last year I think, as I have submitted few patches.

But I can send it again no problem :)

Regards,


Meng


________________________________
De : Andreas Schneider <asn@xxxxxxxxxxxxxx>
Envoyé : mercredi 17 octobre 2018 15:44:59
À : libssh@xxxxxxxxxx
Cc : Meng Hourk Tan
Objet : Re: [PATCH] Set correct state after sending INFO_REQUEST (Kbd Interactive)

On Wednesday, 17 October 2018 15:07:14 CEST Meng Hourk Tan wrote:
> Hello,

Hello Meng,

>
> Here's a patch related to changes from CVE-2018-10933:
>
> Keyboard Interactive Authentication as server always fails (on new packet
> filtering) because SSH_AUTH_STATE_INFO is not correctly set on Keyboard
> Interactive request.
>
> This can be tested with samplesshd-kbdint example.
>
>
> This patch set correct state on keyboard interactive request.

Thanks you very much for your contribution! The patch looks fine.


Could you please send the Certificate of Origin?

See https://git.libssh.org/projects/libssh.git/tree/SubmittingPatches#n15


Thanks,


        Andreas


--
Andreas Schneider                 asn@xxxxxxxxxxxxxx
GPG-ID:     8DFF53E18F2ABC8D8F3C92237EE0FC4DCC014E3D



Follow-Ups:
Re: [PATCH] Set correct state after sending INFO_REQUEST (Kbd Interactive)Andreas Schneider <asn@xxxxxxxxxxxxxx>
Archive administrator: postmaster@lists.cynapses.org