From owner-freebsd-security@FreeBSD.ORG Mon Apr 8 22:41:29 2013 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.FreeBSD.org [8.8.178.115]) by hub.freebsd.org (Postfix) with ESMTP id 6E45A44D for ; Mon, 8 Apr 2013 22:41:29 +0000 (UTC) (envelope-from rsimmons0@gmail.com) Received: from mail-ea0-x234.google.com (mail-ea0-x234.google.com [IPv6:2a00:1450:4013:c01::234]) by mx1.freebsd.org (Postfix) with ESMTP id 0B151C1 for ; Mon, 8 Apr 2013 22:41:28 +0000 (UTC) Received: by mail-ea0-f180.google.com with SMTP id d10so2383320eaj.25 for ; Mon, 08 Apr 2013 15:41:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:x-received:date:message-id:subject:from:to :content-type; bh=BE0/nefxnKcXgpZbtdRzgBg1Lrb/t4UoBT/jkVvVSZ4=; b=c7uuNqWiR4OxSt6bm8GP8gK12ItpbR33xHy+kbtwARDNs+I3vHuosBbC+sPCXwYobk BtjgNbl+asCo6uYw4TRfS08h9L9SEbjbx93JY0NHqVMQkguQEnwQ9LPVvN+9bmnoLAB6 lILhTeeRSNzWDHTzYpoR0xF98x3/vszEfCa79ivjfB1gj9mX+GM5bRNrjPKf03mhqRAq GjiKc5E3eVlNyK6I3QR+BI4dtj67/FBIwNFNsUpoK6nowxeQeSEUoAOC6Wu5hQowQcjU o2LX+Kvw3efHaSM0uEf7lowveePcjeXZTe6zoL84oBSOvyzJ95/iT3oybnb6/GJF9R3J ERCA== MIME-Version: 1.0 X-Received: by 10.15.83.73 with SMTP id b49mr10190019eez.25.1365460888131; Mon, 08 Apr 2013 15:41:28 -0700 (PDT) Received: by 10.14.138.73 with HTTP; Mon, 8 Apr 2013 15:41:28 -0700 (PDT) Date: Mon, 8 Apr 2013 18:41:28 -0400 Message-ID: Subject: CVE-2010-5107 From: Robert Simmons To: freebsd-security Content-Type: text/plain; charset=ISO-8859-1 X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 08 Apr 2013 22:41:29 -0000 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5107 http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/sshd_config.diff?r1=1.88;r2=1.89;f=h I see that the fix for this CVE was recently pulled into HEAD: http://svnweb.freebsd.org/base/head/crypto/openssh/sshd_config?r1=248465&r2=248619 But not yet in stable: http://svnweb.freebsd.org/base/stable/9/crypto/openssh/sshd_config?revision=248468&view=markup Is this change going to be an update to 9.1?