[Bug 1310781] [NEW] bad bignum encoding for curve25519-sha256 at libssh.org

Colin Watson cjwatson at canonical.com
Mon Apr 21 20:32:24 UTC 2014


Public bug reported:

There's an occasional (one in 512 or so) key exchange failure in the
curve25519-sha256 key exchange method, which affects OpenSSH 6.5 and
6.6.  Upstream gives more details here and has recommended that
distributors apply this patch:

  https://lists.mindrot.org/pipermail/openssh-unix-
dev/2014-April/032494.html

We should issue this as an update for trusty.

** Affects: openssh (Ubuntu)
     Importance: High
     Assignee: Colin Watson (cjwatson)
         Status: Triaged

** Changed in: openssh (Ubuntu)
       Status: New => Triaged

** Changed in: openssh (Ubuntu)
   Importance: Undecided => High

** Changed in: openssh (Ubuntu)
     Assignee: (unassigned) => Colin Watson (cjwatson)

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to openssh in Ubuntu.
https://bugs.launchpad.net/bugs/1310781

Title:
  bad bignum encoding for curve25519-sha256 at libssh.org

Status in “openssh” package in Ubuntu:
  Triaged

Bug description:
  There's an occasional (one in 512 or so) key exchange failure in the
  curve25519-sha256 key exchange method, which affects OpenSSH 6.5 and
  6.6.  Upstream gives more details here and has recommended that
  distributors apply this patch:

    https://lists.mindrot.org/pipermail/openssh-unix-
  dev/2014-April/032494.html

  We should issue this as an update for trusty.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openssh/+bug/1310781/+subscriptions



More information about the foundations-bugs mailing list