openssh 1:7.3p1-1 source package in Ubuntu
Changelog
openssh (1:7.3p1-1) unstable; urgency=medium * New upstream release (http://www.openssh.com/txt/release-7.3): - SECURITY: sshd(8): Mitigate a potential denial-of-service attack against the system's crypt(3) function via sshd(8). An attacker could send very long passwords that would cause excessive CPU use in crypt(3). sshd(8) now refuses to accept password authentication requests of length greater than 1024 characters. - SECURITY: ssh(1), sshd(8): Fix observable timing weakness in the CBC padding oracle countermeasures. Note that CBC ciphers are disabled by default and only included for legacy compatibility. - SECURITY: ssh(1), sshd(8): Improve operation ordering of MAC verification for Encrypt-then-MAC (EtM) mode transport MAC algorithms to verify the MAC before decrypting any ciphertext. This removes the possibility of timing differences leaking facts about the plaintext, though no such leakage has been observed. - ssh(1): Add a ProxyJump option and corresponding -J command-line flag to allow simplified indirection through a one or more SSH bastions or "jump hosts". - ssh(1): Add an IdentityAgent option to allow specifying specific agent sockets instead of accepting one from the environment. - ssh(1): Allow ExitOnForwardFailure and ClearAllForwardings to be optionally overridden when using ssh -W. - ssh(1), sshd(8): Implement support for the IUTF8 terminal mode as per draft-sgtatham-secsh-iutf8-00 (closes: #337041, LP: #394570). - ssh(1), sshd(8): Add support for additional fixed Diffie-Hellman 2K, 4K and 8K groups from draft-ietf-curdle-ssh-kex-sha2-03. - ssh-keygen(1), ssh(1), sshd(8): Support SHA256 and SHA512 RSA signatures in certificates. - ssh(1): Add an Include directive for ssh_config(5) files (closes: #536031). - ssh(1): Permit UTF-8 characters in pre-authentication banners sent from the server. - ssh(1), sshd(8): Reduce the syslog level of some relatively common protocol events from LOG_CRIT. - sshd(8): Refuse AuthenticationMethods="" in configurations and accept AuthenticationMethods=any for the default behaviour of not requiring multiple authentication. - sshd(8): Remove obsolete and misleading "POSSIBLE BREAK-IN ATTEMPT!" message when forward and reverse DNS don't match. - ssh(1): Deduplicate LocalForward and RemoteForward entries to fix failures when both ExitOnForwardFailure and hostname canonicalisation are enabled. - sshd(8): Remove fallback from moduli to obsolete "primes" file that was deprecated in 2001 (LP: #1528251). - sshd_config(5): Correct description of UseDNS: it affects ssh hostname processing for authorized_keys, not known_hosts. - sshd(8): Send ClientAliveInterval pings when a time-based RekeyLimit is set; previously keepalive packets were not being sent. - sshd(8): Whitelist more architectures to enable the seccomp-bpf sandbox. - scp(1): Respect the local user's LC_CTYPE locale (closes: #396295). - Take character display widths into account for the progressmeter (closes: #407088). -- Colin Watson <email address hidden> Sun, 07 Aug 2016 22:45:26 +0100
Upload details
- Uploaded by:
- Debian OpenSSH Maintainers
- Uploaded to:
- Sid
- Original maintainer:
- Debian OpenSSH Maintainers
- Architectures:
- any all
- Section:
- net
- Urgency:
- Medium Urgency
See full publishing history Publishing
Series | Published | Component | Section |
---|
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
openssh_7.3p1-1.dsc | 2.8 KiB | 61e8414cb2ed2a72ee15053511d3a2f55ace4b8fb76fff2d901ec67d4a1cf5ba |
openssh_7.3p1.orig.tar.gz | 1.5 MiB | 3ffb989a6dcaa69594c3b550d4855a5a2e1718ccdde7f5e36387b424220fbecc |
openssh_7.3p1-1.debian.tar.xz | 149.8 KiB | a9a96b33427697afb344d6c82078abc54da411f108b19949c9f3378b947b4971 |
Available diffs
- diff from 1:7.2p2-8 to 1:7.3p1-1 (327.0 KiB)
No changes file available.
Binary packages built by this source
- openssh-client: No summary available for openssh-client in ubuntu yakkety.
No description available for openssh-client in ubuntu yakkety.
- openssh-client-dbgsym: No summary available for openssh-client-dbgsym in ubuntu yakkety.
No description available for openssh-
client- dbgsym in ubuntu yakkety.
- openssh-client-ssh1: No summary available for openssh-client-ssh1 in ubuntu yakkety.
No description available for openssh-client-ssh1 in ubuntu yakkety.
- openssh-client-ssh1-dbgsym: No summary available for openssh-client-ssh1-dbgsym in ubuntu zesty.
No description available for openssh-
client- ssh1-dbgsym in ubuntu zesty.
- openssh-client-udeb: No summary available for openssh-client-udeb in ubuntu zesty.
No description available for openssh-client-udeb in ubuntu zesty.
- openssh-client-udeb-dbgsym: No summary available for openssh-client-udeb-dbgsym in ubuntu zesty.
No description available for openssh-
client- udeb-dbgsym in ubuntu zesty.
- openssh-server: No summary available for openssh-server in ubuntu yakkety.
No description available for openssh-server in ubuntu yakkety.
- openssh-server-dbgsym: No summary available for openssh-server-dbgsym in ubuntu yakkety.
No description available for openssh-
server- dbgsym in ubuntu yakkety.
- openssh-server-udeb: No summary available for openssh-server-udeb in ubuntu yakkety.
No description available for openssh-server-udeb in ubuntu yakkety.
- openssh-server-udeb-dbgsym: No summary available for openssh-server-udeb-dbgsym in ubuntu zesty.
No description available for openssh-
server- udeb-dbgsym in ubuntu zesty.
- openssh-sftp-server: No summary available for openssh-sftp-server in ubuntu zesty.
No description available for openssh-sftp-server in ubuntu zesty.
- openssh-sftp-server-dbgsym: No summary available for openssh-sftp-server-dbgsym in ubuntu yakkety.
No description available for openssh-
sftp-server- dbgsym in ubuntu yakkety.
- ssh: No summary available for ssh in ubuntu zesty.
No description available for ssh in ubuntu zesty.
- ssh-askpass-gnome: No summary available for ssh-askpass-gnome in ubuntu zesty.
No description available for ssh-askpass-gnome in ubuntu zesty.
- ssh-askpass-gnome-dbgsym: No summary available for ssh-askpass-gnome-dbgsym in ubuntu yakkety.
No description available for ssh-askpass-
gnome-dbgsym in ubuntu yakkety.
- ssh-krb5: No summary available for ssh-krb5 in ubuntu yakkety.
No description available for ssh-krb5 in ubuntu yakkety.