]> git.ipfire.org Git - thirdparty/openssh-portable.git/commitdiff
upstream commit
authormarkus@openbsd.org <markus@openbsd.org>
Wed, 15 Mar 2017 07:07:39 +0000 (07:07 +0000)
committerDamien Miller <djm@mindrot.org>
Fri, 17 Mar 2017 06:12:44 +0000 (17:12 +1100)
disallow KEXINIT before NEWKEYS; ok djm; report by
vegard.nossum at oracle.com

Upstream-ID: 3668852d1f145050e62f1da08917de34cb0c5234

kex.c

diff --git a/kex.c b/kex.c
index 8ac00299c8cf4f54fcfa365f177ce1274e118f46..cf4ac0dc574d138d8c42e26e8132dfad5b8a017c 100644 (file)
--- a/kex.c
+++ b/kex.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: kex.c,v 1.130 2017/03/10 04:07:20 djm Exp $ */
+/* $OpenBSD: kex.c,v 1.131 2017/03/15 07:07:39 markus Exp $ */
 /*
  * Copyright (c) 2000, 2001 Markus Friedl.  All rights reserved.
  *
@@ -341,7 +341,6 @@ kex_reset_dispatch(struct ssh *ssh)
 {
        ssh_dispatch_range(ssh, SSH2_MSG_TRANSPORT_MIN,
            SSH2_MSG_TRANSPORT_MAX, &kex_protocol_error);
-       ssh_dispatch_set(ssh, SSH2_MSG_KEXINIT, &kex_input_kexinit);
 }
 
 static int
@@ -431,6 +430,7 @@ kex_input_newkeys(int type, u_int32_t seq, void *ctxt)
 
        debug("SSH2_MSG_NEWKEYS received");
        ssh_dispatch_set(ssh, SSH2_MSG_NEWKEYS, &kex_protocol_error);
+       ssh_dispatch_set(ssh, SSH2_MSG_KEXINIT, &kex_input_kexinit);
        if ((r = sshpkt_get_end(ssh)) != 0)
                return r;
        if ((r = ssh_set_newkeys(ssh, MODE_IN)) != 0)
@@ -545,6 +545,7 @@ kex_new(struct ssh *ssh, char *proposal[PROPOSAL_MAX], struct kex **kexp)
                goto out;
        kex->done = 0;
        kex_reset_dispatch(ssh);
+       ssh_dispatch_set(ssh, SSH2_MSG_KEXINIT, &kex_input_kexinit);
        r = 0;
        *kexp = kex;
  out: