3 ms·
Well, I looked at both patches and didn't like either one of them. The user 'manfred-kaiser' makes a good point and I have confirmed that he is correct. Howeve
by Randor 5y ago
Well,
I looked at both patches and didn't like either one of them. The user 'manfred-kaiser' makes a good point and I have confirmed that he is correct. However the fix he is proposing is not a very good fix. So in my opinion both of the proposed fixes are not sufficient.
The proposed fix: https://github.com/openssh/openssh-portable/commit/b3855ff053f5078ec3d3c653cdaedefaa5fc362d https://github.com/openssh/openssh-portable/commit/b3855ff05...
This proposed fix means OpenSSH is not secure 'by default' and would require HostKeyAlgorithms to be set in the config file. Furthermore... there needs to be an existing public key. Also keep in mind that SSHD refuses to use group/world-accessible keys.
So if this patch is accepted CVE-2020-14145 will continue to work on 'misconfigured' servers.
"It's not our fault, your OpenSSH was misconfigured!"