From owner-freebsd-security@FreeBSD.ORG Sat Nov 9 16:24:54 2013 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTP id 036165DE for ; Sat, 9 Nov 2013 16:24:54 +0000 (UTC) (envelope-from mailnull@mips.inka.de) Received: from mail-in-05.arcor-online.net (mail-in-05.arcor-online.net [151.189.21.45]) (using TLSv1 with cipher ADH-CAMELLIA256-SHA (256/256 bits)) (No client certificate requested) by mx1.freebsd.org (Postfix) with ESMTPS id AFFC52774 for ; Sat, 9 Nov 2013 16:24:53 +0000 (UTC) Received: from mail-in-17-z2.arcor-online.net (mail-in-17-z2.arcor-online.net [151.189.8.34]) by mx.arcor.de (Postfix) with ESMTP id 6EA87E4227 for ; Sat, 9 Nov 2013 17:24:45 +0100 (CET) Received: from mail-in-10.arcor-online.net (mail-in-10.arcor-online.net [151.189.21.50]) by mail-in-17-z2.arcor-online.net (Postfix) with ESMTP id 55B10110A2C for ; Sat, 9 Nov 2013 17:24:45 +0100 (CET) X-Greylist: Passed host: 94.218.177.33 X-DKIM: Sendmail DKIM Filter v2.8.2 mail-in-10.arcor-online.net 189A92D6301 Received: from lorvorc.mips.inka.de (dslb-094-218-177-033.pools.arcor-ip.net [94.218.177.33]) by mail-in-10.arcor-online.net (Postfix) with ESMTPS id 189A92D6301 for ; Sat, 9 Nov 2013 17:24:43 +0100 (CET) Received: from lorvorc.mips.inka.de (localhost [127.0.0.1]) by lorvorc.mips.inka.de (8.14.7/8.14.7) with ESMTP id rA9FCc7W017268 for ; Sat, 9 Nov 2013 16:12:38 +0100 (CET) (envelope-from mailnull@lorvorc.mips.inka.de) Received: (from mailnull@localhost) by lorvorc.mips.inka.de (8.14.7/8.14.7/Submit) id rA9FCcDC017267 for freebsd-security@freebsd.org; Sat, 9 Nov 2013 16:12:38 +0100 (CET) (envelope-from mailnull) From: naddy@mips.inka.de (Christian Weisgerber) Subject: Re: openssh gcmrekey Date: Sat, 9 Nov 2013 15:12:38 +0000 (UTC) Message-ID: References: <20131108131727.GA38453@zxy.spb.ru> Originator: naddy@mips.inka.de (Christian Weisgerber) To: freebsd-security@freebsd.org X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 09 Nov 2013 16:24:54 -0000 Slawa Olhovchenkov wrote: > 2. Affected configurations > OpenSSH 6.2 and OpenSSH 6.3 when built against an OpenSSL > that supports AES-GCM. > > ===== > > FreeBSD affected? FreeBSD 9 is not affected, because the OpenSSL there is too old and doesn't support AES-GCM (cf. PR #179619). FreeBSD 10+ is affected. -- Christian "naddy" Weisgerber naddy@mips.inka.de