diff options
author | Colin Watson <cjwatson@debian.org> | 2018-08-17 12:28:26 +0100 |
---|---|---|
committer | Colin Watson <cjwatson@debian.org> | 2018-08-17 12:31:27 +0100 |
commit | 4641c58a3279f6b118f9562babaa0ee050a38619 (patch) | |
tree | 87718b668ec8a737c1729ee568207c2a384f6d61 /debian/changelog | |
parent | daf34b85afe25c10fac13e9cff16b25c3e3914e9 (diff) | |
parent | c4ca1497658e0508e8595ad74978c07bc92a18e3 (diff) |
Fix user enumeration vulnerability
Apply upstream patch to delay bailout for invalid authenticating user
until after the packet containing the request has been fully parsed.
Closes: #906236
Diffstat (limited to 'debian/changelog')
-rw-r--r-- | debian/changelog | 8 |
1 files changed, 8 insertions, 0 deletions
diff --git a/debian/changelog b/debian/changelog index 15024f76b..d9de16199 100644 --- a/debian/changelog +++ b/debian/changelog | |||
@@ -1,3 +1,11 @@ | |||
1 | openssh (1:7.7p1-4) UNRELEASED; urgency=high | ||
2 | |||
3 | * Apply upstream patch to delay bailout for invalid authenticating user | ||
4 | until after the packet containing the request has been fully parsed | ||
5 | (closes: #906236). | ||
6 | |||
7 | -- Colin Watson <cjwatson@debian.org> Fri, 17 Aug 2018 12:30:13 +0100 | ||
8 | |||
1 | openssh (1:7.7p1-3) unstable; urgency=medium | 9 | openssh (1:7.7p1-3) unstable; urgency=medium |
2 | 10 | ||
3 | [ Colin Watson ] | 11 | [ Colin Watson ] |