Files
libssh/include/libssh
Jakub Jelen f5211239f9 CVE-2021-3634: Create a separate length for session_id
Normally, the length of session_id and secret_hash is the same,
but if we will get into rekeying with a peer that changes preference
of key exchange algorithm, the new secret hash can be larger or
smaller than the previous session_id causing invalid reads or writes.

Resolves https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=35485

Signed-off-by: Jakub Jelen <jjelen@redhat.com>
Reviewed-by: Andreas Schneider <asn@cryptomilk.org>
2021-08-18 14:13:56 +02:00
..
2019-01-24 13:06:33 +01:00
2019-08-08 09:30:03 +02:00
2019-01-24 09:19:59 +01:00
2019-12-23 14:45:24 +01:00
2018-06-28 08:41:08 +02:00
2019-12-20 16:17:33 +01:00
2016-05-02 16:40:43 +02:00
2021-06-10 09:22:32 +02:00
2013-01-23 00:22:46 +01:00
2020-08-12 13:13:13 +02:00
2013-01-23 00:22:46 +01:00