[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH] Set correct state after sending INFO_REQUEST (Kbd Interactive)


On Wednesday, 17 October 2018 15:07:14 CEST Meng Hourk Tan wrote:
> Hello,

Hello Meng,
 
> 
> Here's a patch related to changes from CVE-2018-10933:
> 
> Keyboard Interactive Authentication as server always fails (on new packet
> filtering) because SSH_AUTH_STATE_INFO is not correctly set on Keyboard
> Interactive request.
> 
> This can be tested with samplesshd-kbdint example.
> 
> 
> This patch set correct state on keyboard interactive request.

Thanks you very much for your contribution! The patch looks fine.


Could you please send the Certificate of Origin?

See https://git.libssh.org/projects/libssh.git/tree/SubmittingPatches#n15


Thanks,


	Andreas


-- 
Andreas Schneider                 asn@xxxxxxxxxxxxxx
GPG-ID:     8DFF53E18F2ABC8D8F3C92237EE0FC4DCC014E3D



Archive administrator: postmaster@lists.cynapses.org