summaryrefslogtreecommitdiff
path: root/debian/changelog
diff options
context:
space:
mode:
authorColin Watson <cjwatson@debian.org>2018-08-17 12:28:26 +0100
committerColin Watson <cjwatson@debian.org>2018-08-17 12:31:27 +0100
commit4641c58a3279f6b118f9562babaa0ee050a38619 (patch)
tree87718b668ec8a737c1729ee568207c2a384f6d61 /debian/changelog
parentdaf34b85afe25c10fac13e9cff16b25c3e3914e9 (diff)
parentc4ca1497658e0508e8595ad74978c07bc92a18e3 (diff)
Fix user enumeration vulnerability
Apply upstream patch to delay bailout for invalid authenticating user until after the packet containing the request has been fully parsed. Closes: #906236
Diffstat (limited to 'debian/changelog')
-rw-r--r--debian/changelog8
1 files changed, 8 insertions, 0 deletions
diff --git a/debian/changelog b/debian/changelog
index 15024f76b..d9de16199 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -1,3 +1,11 @@
1openssh (1:7.7p1-4) UNRELEASED; urgency=high
2
3 * Apply upstream patch to delay bailout for invalid authenticating user
4 until after the packet containing the request has been fully parsed
5 (closes: #906236).
6
7 -- Colin Watson <cjwatson@debian.org> Fri, 17 Aug 2018 12:30:13 +0100
8
1openssh (1:7.7p1-3) unstable; urgency=medium 9openssh (1:7.7p1-3) unstable; urgency=medium
2 10
3 [ Colin Watson ] 11 [ Colin Watson ]