openssh 1:8.4p1-5+deb11u3 source package in Debian

Changelog

openssh (1:8.4p1-5+deb11u3) bullseye-security; urgency=medium

  * Cherry-pick from upstream:
    - [CVE-2021-41617]: sshd(8) from OpenSSH 6.2 through 8.7 failed to
      correctly initialise supplemental groups when executing an
      AuthorizedKeysCommand or AuthorizedPrincipalsCommand, where a
      AuthorizedKeysCommandUser or AuthorizedPrincipalsCommandUser directive
      has been set to run the command as a different user. Instead these
      commands would inherit the groups that sshd(8) was started with
      (closes: #995130).
    - [CVE-2023-48795] ssh(1), sshd(8): implement protocol extensions to
      thwart the so-called "Terrapin attack" discovered by Fabian Bäumer,
      Marcus Brinkmann and Jörg Schwenk. This attack allows a MITM to effect
      a limited break of the integrity of the early encrypted SSH transport
      protocol by sending extra messages prior to the commencement of
      encryption, and deleting an equal number of consecutive messages
      immediately after encryption starts. A peer SSH client/server would
      not be able to detect that messages were deleted.
    - [CVE-2023-51385] ssh(1): if an invalid user or hostname that contained
      shell metacharacters was passed to ssh(1), and a ProxyCommand,
      LocalCommand directive or "match exec" predicate referenced the user
      or hostname via %u, %h or similar expansion token, then an attacker
      who could supply arbitrary user/hostnames to ssh(1) could potentially
      perform command injection depending on what quoting was present in the
      user-supplied ssh_config(5) directive. ssh(1) now bans most shell
      metacharacters from user and hostnames supplied via the command-line.

 -- Colin Watson <email address hidden>  Thu, 21 Dec 2023 16:09:44 +0000

Upload details

Uploaded by:
Debian OpenSSH Maintainers
Uploaded to:
Bullseye
Original maintainer:
Debian OpenSSH Maintainers
Architectures:
any all
Section:
net
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Bullseye release main net

Builds

Downloads

File Size SHA-256 Checksum
openssh_8.4p1-5+deb11u3.dsc 3.2 KiB 0f800a412ac707c735afd90b5529511c5c1629b6aef342d824b2f66250565459
openssh_8.4p1.orig.tar.gz 1.7 MiB 5a01d22e407eb1c05ba8a8f7c654d388a13e9f226e4ed33bd38748dafa1d2b24
openssh_8.4p1.orig.tar.gz.asc 683 bytes ccd9dd484651ce4cc926228f6e1b46afaf0c5ab98a866217fa0ef1074370ea2b
openssh_8.4p1-5+deb11u3.debian.tar.xz 182.2 KiB f460cc974def7a03753f6d3e5248265aa01deca7e2ba5e29979677487e89cd41

No changes file available.

Binary packages built by this source