Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dropbear: T6195: package upgrade 2022.83-1+deb12u1 #547

Merged
merged 3 commits into from
Apr 1, 2024
Merged

Commits on Apr 1, 2024

  1. Jenkins: remove Debian build dependency files from the workspace

    No need to provide them via the package repository
    c-po committed Apr 1, 2024
    Configuration menu
    Copy the full SHA
    adab6ba View commit details
    Browse the repository at this point in the history
  2. dropbear: T6195: package upgrade 2022.83-1+deb12u1

    Fix CVE-2023-48795: (terrapin attack)
    
    The SSH transport protocol with certain OpenSSH extensions allows remote
    attackers to bypass integrity checks such that some packets are omitted (from
    the extension negotiation message), and a client and server may consequently
    end up with a connection for which some security features have been downgraded
    or disabled, aka a Terrapin attack.
    c-po committed Apr 1, 2024
    Configuration menu
    Copy the full SHA
    b17befe View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    4417986 View commit details
    Browse the repository at this point in the history