| commit | 13ae44ce5865b720708aae9cb1d2e2f08a0d90cb | [log] [download] |
|---|---|---|
| author | Damien Miller <djm@mindrot.org> | Wed Jan 28 16:38:41 2009 +1100 |
| committer | Damien Miller <djm@mindrot.org> | Wed Jan 28 16:38:41 2009 +1100 |
| tree | b9acd30c2e1edfa1a4b7dcc26b8c11f8ea77b855 | |
| parent | 9aa72ba57af907af8f7228f64fca8a474797898f [diff] |
- markus@cvs.openbsd.org 2009/01/26 09:58:15
[cipher.c cipher.h packet.c]
Work around the CPNI-957037 Plaintext Recovery Attack by always
reading 256K of data on packet size or HMAC errors (in CBC mode only).
Help, feedback and ok djm@
Feedback from Martin Albrecht and Paterson Kenny