]> CyberLeo.Net >> Repos - FreeBSD/FreeBSD.git/commit
Apply upstream fix for CVE-2016-10009 and CVE-2016-10010:
authordelphij <delphij@FreeBSD.org>
Wed, 11 Jan 2017 05:42:06 +0000 (05:42 +0000)
committerdelphij <delphij@FreeBSD.org>
Wed, 11 Jan 2017 05:42:06 +0000 (05:42 +0000)
commit87ff7d220606ad76e4059f6d46dd01a342643300
tree2ca10808770781c0ec6670edd0f06416e96e9268
parentaee5ba51da67c4f585832472e4b06650506edfda
Apply upstream fix for CVE-2016-10009 and CVE-2016-10010:

  add a whitelist of paths from which ssh-agent will load (via
  ssh-pkcs11-helper) a PKCS#11 module; ok markus@

  disable Unix-domain socket forwarding when privsep is disabled

(Note that this is a backport of upstream fixes, and this commit
is mainly to ease future imports).

Obtained from:  OpenBSD
serverloop.c
ssh-agent.1
ssh-agent.c