2017-08-10 06:36:37 - r322341 by delphij (Xin LI)

Complete list of files affected by revision r322341:

  History   Contents   Diff   MODIFY   /stable/10/crypto/openssh/auth-passwd.c  
  History   Contents   Diff   MODIFY   /stable/11/crypto/openssh/auth-passwd.c  

Commit message:

Apply upstream fix:

Skip passwords longer than 1k in length so clients can't
easily DoS sshd by sending very long passwords, causing it to spend CPU
hashing them. feedback djm@, ok markus@.

Brought to our attention by tomas.kuthan at, shilei-c at and coredump at

Security: CVE-2016-6515
Security: FreeBSD-SA-17:06.openssh


