DELTA 428542 0 288108 SVN y N _n C9 v\x^Un0S;RukRxuŖ%?.%ۏrt>"庮B_Qx EY6 ՠ< gwh4Sw:<|!e\:04 b Fa)B+Z*:)W#ؔo^0@ ldBh|AػBq&9ȣC&bb\3$w'%ꊎӚ)c IllsqM9*\*389~.A/~j(rnC^TiRSuf#f ~f8={Y].Ka)O'M9ɘRlɺ{vps/=vam״Oƶ 5 J@3 C} @?3
When processing the SSH_MSG_KEXINIT message, the server could allocate up to a few hundreds of megabytes of memory per each connection, before any authentication take place.
A remote attacker may be able to cause a SSH server to allocate an excessive amount of memory. Note that the default MaxStartups setting on FreeBSD will limit the effectiveness of this attack.