3 ms·
This is client-only vulnerability: The matching server code has never been shipped, but the client code was enabled by default and could be tricked by a
by aexaey 11y ago
This is client-only vulnerability:
The matching server code has never been shipped, but the client
code was enabled by default and could be tricked by a malicious
server into leaking client memory to the server, including private
client user keys.[1]
[1] https://lists.mindrot.org/pipermail/openssh-unix-dev/2016-January/034680.html https://lists.mindrot.org/pipermail/openssh-unix-dev/2016-Ja...