diff options
Diffstat (limited to 'debian')
-rw-r--r-- | debian/changelog | 31 |
1 files changed, 29 insertions, 2 deletions
diff --git a/debian/changelog b/debian/changelog index eaab6b72b..a057465b2 100644 --- a/debian/changelog +++ b/debian/changelog | |||
@@ -1,5 +1,32 @@ | |||
1 | openssh (1:5.1p1-9) UNRELEASED; urgency=low | 1 | openssh (1:5.2p1-1) UNRELEASED; urgency=low |
2 | 2 | ||
3 | * New upstream release (closes: #536182). Yes, I know 5.3p1 has been out | ||
4 | for a while, but there's no GSSAPI patch available for it yet. | ||
5 | - Change the default cipher order to prefer the AES CTR modes and the | ||
6 | revised "arcfour256" mode to CBC mode ciphers that are susceptible to | ||
7 | CPNI-957037 "Plaintext Recovery Attack Against SSH". | ||
8 | - Add countermeasures to mitigate CPNI-957037-style attacks against the | ||
9 | SSH protocol's use of CBC-mode ciphers. Upon detection of an invalid | ||
10 | packet length or Message Authentication Code, ssh/sshd will continue | ||
11 | reading up to the maximum supported packet length rather than | ||
12 | immediately terminating the connection. This eliminates most of the | ||
13 | known differences in behaviour that leaked information about the | ||
14 | plaintext of injected data which formed the basis of this attack | ||
15 | (closes: #506115, LP: #379329). | ||
16 | - ForceCommand directive now accepts commandline arguments for the | ||
17 | internal-sftp server (closes: #524423, LP: #362511). | ||
18 | - Add AllowAgentForwarding to available Match keywords list (closes: | ||
19 | #540623). | ||
20 | - Make ssh(1) send the correct channel number for | ||
21 | SSH2_MSG_CHANNEL_SUCCESS and SSH2_MSG_CHANNEL_FAILURE messages to | ||
22 | avoid triggering 'Non-public channel' error messages on sshd(8) in | ||
23 | openssh-5.1. | ||
24 | - Avoid printing 'Non-public channel' warnings in sshd(8), since the | ||
25 | ssh(1) has sent incorrect channel numbers since ~2004 (this reverts a | ||
26 | behaviour introduced in openssh-5.1; closes: #496017). | ||
27 | * Update to GSSAPI patch from | ||
28 | http://www.sxw.org.uk/computing/patches/openssh-5.2p1-gsskex-all-20090726.patch, | ||
29 | including cascading credentials support (LP: #416958). | ||
3 | * Use x11.pc when compiling/linking gnome-ssh-askpass2 (closes: #555951). | 30 | * Use x11.pc when compiling/linking gnome-ssh-askpass2 (closes: #555951). |
4 | * Moved to bzr.debian.org; add Vcs-Bzr and Vcs-Browser control fields. | 31 | * Moved to bzr.debian.org; add Vcs-Bzr and Vcs-Browser control fields. |
5 | * Add debian/README.source with instructions on bzr handling. | 32 | * Add debian/README.source with instructions on bzr handling. |