SSHd crash with SecureCRT NO-OP

Bug #968801 reported by Gerald Villemure
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenSSL
Fix Released
Unknown
openssl (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

The moment SecureCRT (SSH client) sends a NO-OP packet, SSHd crashes with this error:
   sshd[1701]: segfault at b9552000 ip b75299f8 sp bfd52370 error 6 in libcrypto.so.1.0.0[b74d1000+192000]

Debian has a related bug: Bug#665836

I have the problem with:
   libssl1.0.0_1.0.1-2ubuntu2
It works fine with:
  libssl1.0.0_1.0.0e-2ubuntu4

What is strange is if I use the OpenSSH client:
   ssh -o 'ServerAliveInterval 10' server
or I use the PUTTY client I am unable to reproduce the crash.

Its tempting to simply say that its a SecureCRT bug and leave it at that, but I would rather not have SSHd so easy to crash.

Gérald

Changed in openssl:
status: Unknown → New
Changed in openssl:
status: New → Confirmed
Changed in openssl:
status: Confirmed → Fix Released
Revision history for this message
Gerald Villemure (gvillemure) wrote :

Its been a week, when will the fix be available in the repos?

The bug is still there with: libssl1.0.0_1.0.1-2ubuntu4

FYI, There is an official patch for the vpaes problem.

Gérald

Revision history for this message
Gerald Villemure (gvillemure) wrote :

I am please to say that the problem is no longer there with: libssl1.0.0_1.0.1-4ubuntu1

Gérald

Revision history for this message
Maarten Bezemer (veger) wrote :

This bug report is being closed due to your last comment regarding this being fixed with an update. For future reference you can manage the status of your own bugs by clicking on the current status in the yellow line and then choosing a new status in the revealed drop down box. You can learn more about bug statuses at https://wiki.ubuntu.com/Bugs/Status. Thank you again for taking the time to report this bug and helping to make Ubuntu better. Please submit any future bugs you may find.

Changed in openssl (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.