Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dropbear: T6195: package upgrade 2022.83-1+deb12u1 (backport #547) #548

Merged
merged 3 commits into from
Apr 1, 2024

Conversation

mergify[bot]
Copy link

@mergify mergify bot commented Apr 1, 2024

Change Summary

Fix CVE-2023-48795: (terrapin attack)

The SSH transport protocol with certain OpenSSH extensions allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack.

Also no longer upload build dependency files to the repo

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Code style update (formatting, renaming)
  • Refactoring (no functional changes)
  • Migration from an old Vyatta component to vyos-1x, please link to related PR inside obsoleted component
  • Other (please describe):

Related Task(s)

Component(s) name

dropbear

Proposed changes

How to test

Checklist:

  • I have read the CONTRIBUTING document
  • I have linked this PR to one or more Phabricator Task(s)
  • My commit headlines contain a valid Task id
  • My change requires a change to the documentation
  • I have updated the documentation accordingly

This is an automatic backport of pull request #547 done by [Mergify](https://mergify.com).

c-po added 3 commits April 1, 2024 14:12
No need to provide them via the package repository

(cherry picked from commit adab6ba)
Fix CVE-2023-48795: (terrapin attack)

The SSH transport protocol with certain OpenSSH extensions allows remote
attackers to bypass integrity checks such that some packets are omitted (from
the extension negotiation message), and a client and server may consequently
end up with a connection for which some security features have been downgraded
or disabled, aka a Terrapin attack.

(cherry picked from commit b17befe)
@vyosbot vyosbot requested review from a team, dmbaturin, sarthurdev, zdc, jestabro, sever-sever and c-po and removed request for a team April 1, 2024 14:12
@github-actions github-actions bot added the sagitta VyOS 1.4 LTS label Apr 1, 2024
@c-po c-po merged commit 3d771a3 into sagitta Apr 1, 2024
4 checks passed
@mergify mergify bot deleted the mergify/bp/sagitta/pr-547 branch April 1, 2024 14:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
sagitta VyOS 1.4 LTS
2 participants