Age | Commit message (Collapse) | Author | |
---|---|---|---|
2019-06-09 | New upstream release (8.0p1) | Colin Watson | |
2019-04-08 | Temporarily revert IPQoS defaults to pre-7.8 values | Colin Watson | |
This is just until issues with "iptables -m tos" and VMware have been fixed. Closes: #923879, #926229 LP: #1822370 | |||
2019-03-01 | Handle shell-style brace expansions in scp checks | Colin Watson | |
2019-02-28 | Request RSA-SHA2 signatures for corresponding cert algorithms | Colin Watson | |
Closes: #923419 | |||
2019-02-28 | Fix key type checks with RSA-SHA2 signature types | Colin Watson | |
2019-02-08 | scp: Check remote->local directory copy filenames | Colin Watson | |
CVE-2019-6111 | |||
2019-02-08 | Sanitize scp filenames via snmprintf | Colin Watson | |
CVE-2019-6109 Closes: #793412 | |||
2019-01-12 | scp: disallow empty incoming filename or "." | Colin Watson | |
Closes: #919101 | |||
2018-10-20 | New upstream release (7.9p1) | Colin Watson | |
2018-08-30 | Work around conch interoperability failure | Colin Watson | |
Twisted Conch fails to read private keys in the new format (https://twistedmatrix.com/trac/ticket/9515). Work around this until it can be fixed in Twisted. | |||
2018-08-30 | New upstream release (7.8p1) | Colin Watson | |
Closes: #907534 | |||
2018-08-17 | Fix user enumeration vulnerability | Colin Watson | |
Apply upstream patch to delay bailout for invalid authenticating user until after the packet containing the request has been fully parsed. Closes: #906236 | |||
2018-06-28 | [ Christian Ehrhardt ] | Christian Ehrhardt | |
Fix unintentional restriction of authorized keys environment options to be alphanumeric (LP: #1771011) | |||
2018-04-03 | Fix parsing of DebianBanner option | Colin Watson | |
Closes: #894730 | |||
2018-04-03 | New upstream release (7.7p1) | Colin Watson | |
2018-01-16 | Fix putty-transfer regression test. | Colin Watson | |
2017-10-07 | Apply upstream patch to fix PermitOpen argument handling. | Colin Watson | |
2017-10-05 | New upstream release (7.6p1) | Colin Watson | |
2017-08-28 | Apply patches from https://bugzilla.mindrot.org/show_bug.cgi?id=2752 to ↵ | Colin Watson | |
allow some extra syscalls for crypto cards on s390x (LP: #1686618). | |||
2017-08-22 | Quote IP address in suggested "ssh-keygen -f" calls (closes: #872643). | Colin Watson | |
2017-08-22 | Drop Upstart-specific patches | Colin Watson | |
2017-06-06 | Fix incoming compression statistics (thanks, Russell Coker; closes: #797964). | Colin Watson | |
2017-04-02 | Fix syntax error on Linux/X32 | Colin Watson | |
2017-04-02 | Add missing header on Linux/s390 | Colin Watson | |
2017-04-02 | New upstream release (7.5p1) | Colin Watson | |
2017-03-30 | Unbreak Unix domain socket forwarding for root (closes: #858252). | Colin Watson | |
2017-03-16 | Fix null pointer dereference in ssh-keygen; this fixes an autopkgtest ↵ | Colin Watson | |
regression introduced in 1:7.4p1-8. | |||
2017-03-14 | Fix ssh-keyscan to correctly hash hosts with a port number (closes: #857736, ↵ | Colin Watson | |
LP: #1670745). | |||
2017-03-09 | Fix ssh-keygen -H accidentally corrupting known_hosts that contained ↵ | Colin Watson | |
already-hashed entries (closes: #851734, LP: #1668093). | |||
2017-03-05 | Restore reading authorized_keys2 by default | Colin Watson | |
Upstream seems to intend to gradually phase this out, so don't assume that this will remain the default forever. However, we were late in adopting the upstream sshd_config changes, so it makes sense to extend the grace period (closes: #852320). | |||
2017-01-16 | Fix rekeying failure with GSSAPI key exchange (thanks, Harald Barth; closes: ↵ | Colin Watson | |
#819361). | |||
2017-01-16 | Remove ssh_host_dsa_key from HostKey default (closes: #850614). | Colin Watson | |
2017-01-03 | Work around clock_gettime kernel bug on Linux x32 (closes: #849923). | Colin Watson | |
2017-01-03 | Create mux socket for regression tests in a temporary directory. | Colin Watson | |
2017-01-02 | merge patched into master | Colin Watson | |
2017-01-01 | Make integrity tests more robust against timeouts in the case where the ↵ | Colin Watson | |
first test in a series for a given MAC happens to modify the low bytes of a packet length. | |||
2016-12-28 | Avoid calling into Kerberos libraries from ssh_gssapi_server_mechanisms in ↵ | Colin Watson | |
the privsep monitor. | |||
2016-12-26 | Remove redundant "GSSAPIDelegateCredentials no" from ssh_config (already the ↵ | Colin Watson | |
upstream default), and document that setting ServerAliveInterval to 300 by default if BatchMode is set is Debian-specific (closes: #765630). | |||
2016-12-26 | Start handling /etc/ssh/sshd_config using ucf. | Colin Watson | |
* Start handling /etc/ssh/sshd_config using ucf. The immediate motivation for this is to deal with deprecations of options related to protocol 1, but something like this has been needed for a long time (closes: #419574, #848089): - sshd_config is now a slightly-patched version of upstream's, and only contains non-default settings (closes: #147201). - I've included as many historical md5sums of default versions of sshd_config as I could reconstruct from version control, but I'm sure I've missed some. - Explicitly synchronise the debconf database with the current configuration file state in openssh-server.config, to ensure that the PermitRootLogin setting is properly preserved. - UsePrivilegeSeparation now defaults to the stronger "sandbox" rather than "yes", per upstream. | |||
2016-12-23 | New upstream release (7.4p1). | Colin Watson | |
2016-11-19 | Fix and enable PuTTY interoperability tests under autopkgtest. | Colin Watson | |
2016-10-24 | CVE-2016-8858: Unregister the KEXINIT handler after message has been ↵ | Colin Watson | |
received (closes: #841884). | |||
2016-08-07 | New upstream release (7.3p1). | Colin Watson | |
2016-07-22 | Backport upstream patch to close ControlPersist background process stderr ↵ | Colin Watson | |
when not in debug mode or when logging to a file or syslog (closes: #714526). | |||
2016-07-22 | CVE-2016-6210: Mitigate user enumeration via covert timing channel. | Colin Watson | |
2016-04-28 | Backport upstream patch to unbreak authentication using lone certificate ↵ | Colin Watson | |
keys in ssh-agent: when attempting pubkey auth with a certificate, if no separate private key is found among the keys then try with the certificate key itself (thanks, Paul Querna; LP: #1575961). | |||
2016-04-13 | CVE-2015-8325: Ignore PAM environment vars when UseLogin=yes. | Colin Watson | |
2016-03-21 | Fix kexgss_server to cope with DH_GRP_MIN/DH_GRP_MAX being stricter on the ↵ | Colin Watson | |
server end than the client (thanks, Damien Miller; closes: #817870, LP: #1558576). | |||
2016-03-10 | New upstream release (7.2p2). | Colin Watson | |
2016-03-08 | New upstream release (7.2). | Colin Watson | |