Format: 1.8 Date: Sat, 09 Apr 2022 14:14:10 +0100 Source: openssh Binary: openssh-client openssh-server openssh-sftp-server openssh-tests ssh ssh-askpass-gnome Built-For-Profiles: noudeb Architecture: amd64 amd64_translations all Version: 1:9.0p1-1 Distribution: kinetic-proposed Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Colin Watson Description: openssh-client - secure shell (SSH) client, for secure access to remote machines openssh-server - secure shell (SSH) server, for secure access from remote machines openssh-sftp-server - secure shell (SSH) sftp server module, for SFTP access from remot openssh-tests - OpenSSH regression tests ssh - secure shell client and server (metapackage) ssh-askpass-gnome - interactive X program to prompt users for a passphrase for ssh-ad Closes: 144579 204546 327019 1007822 Changes: openssh (1:9.0p1-1) unstable; urgency=medium . * New upstream release (https://www.openssh.com/releasenotes.html#9.0p1): - scp(1): Use the SFTP protocol by default (closes: #144579, #204546, #327019). This changes scp's quoting semantics by no longer performing wildcard expansion using the remote shell, and (with some server versions) no longer expanding ~user paths. The -O option is available to use the old protocol. See NEWS.Debian for more details. - ssh(1), sshd(8): use the hybrid Streamlined NTRU Prime + x25519 key exchange method by default ("sntrup761x25519-sha512@openssh.com"). The NTRU algorithm is believed to resist attacks enabled by future quantum computers and is paired with the X25519 ECDH key exchange (the previous default) as a backstop against any weaknesses in NTRU Prime that may be discovered in the future. The combination ensures that the hybrid exchange offers at least as good security as the status quo. - sftp-server(8): support the "copy-data" extension to allow server- side copying of files/data, following the design in draft-ietf-secsh-filexfer-extensions-00. - sftp(1): add a "cp" command to allow the sftp client to perform server-side file copies. - ssh(1), sshd(8): upstream: fix poll(2) spin when a channel's output fd closes without data in the channel buffer (closes: #1007822). - sshd(8): pack pollfd array in server listen/accept loop. Could cause the server to hang/spin when MaxStartups > RLIMIT_NOFILE. - ssh-keygen(1): avoid NULL deref via the find-principals and check-novalidate operations. bz3409 and GHPR307 respectively. - scp(1): fix a memory leak in argument processing. - sshd(8): don't try to resolve ListenAddress directives in the sshd re-exec path. They are unused after re-exec and parsing errors (possible for example if the host's network configuration changed) could prevent connections from being accepted. - sshd(8): when refusing a public key authentication request from a client for using an unapproved or unsupported signature algorithm include the algorithm name in the log message to make debugging easier. - ssh(1), sshd(8): Fix possible integer underflow in scan_scaled(3) parsing of K/M/G/etc quantities. - sshd(8): default to not using sandbox when cross compiling. On most systems poll(2) does not work when the number of FDs is reduced with setrlimit, so assume it doesn't when cross compiling and we can't run the test. * Remove obsolete FAQ, removed from openssh.com in 2016. Checksums-Sha1: 12c065fa0f55be34ae9cd6a9b16116c1a1b1bdad 3016756 openssh-client-dbgsym_9.0p1-1_amd64.ddeb a4e1879a4322f242b924ac744afa66b403b921d4 896630 openssh-client_9.0p1-1_amd64.deb 326e162ab65fd4f3407c056822abaf4204bac6d5 970816 openssh-server-dbgsym_9.0p1-1_amd64.ddeb b8f0a9a97287592c66f43c9b8431e00097c54547 436046 openssh-server_9.0p1-1_amd64.deb a323cdebaf47bd3d95ad39c7d42a903c00416751 114228 openssh-sftp-server-dbgsym_9.0p1-1_amd64.ddeb bdeef081e5afc1e13423b10ba15a9c9cc6873cf9 39918 openssh-sftp-server_9.0p1-1_amd64.deb 4a40806d77ec1ac7328d8ee589c54838e19380f7 1529478 openssh-tests-dbgsym_9.0p1-1_amd64.ddeb 09528a78836514e944a2c4fe19f156b4cbbae933 1417682 openssh-tests_9.0p1-1_amd64.deb fe59177f849ebb3cc46e5be3d98db20bbe224507 18076 openssh_9.0p1-1_amd64.buildinfo a3f24c7cc3eba682b69f2713efbc232e105ebcce 8526 openssh_9.0p1-1_amd64_translations.tar.gz d189cf674518d39d90e1f271baa17f796192d240 17220 ssh-askpass-gnome-dbgsym_9.0p1-1_amd64.ddeb f8ecde97b4476034dfaee24e548eb6e4c6f49c81 17982 ssh-askpass-gnome_9.0p1-1_amd64.deb 78f117d1cb125b16ebdaddb8e858af935ac201b0 4832 ssh_9.0p1-1_all.deb Checksums-Sha256: 686e89a4f312e28d4a222fdfc6df636bfd64b2bfa7eb562e7f0d27993a262383 3016756 openssh-client-dbgsym_9.0p1-1_amd64.ddeb 334c75a678beaa31a7b09dae1d21064d905e7fc9fa3630b42cae2a4e24d56317 896630 openssh-client_9.0p1-1_amd64.deb 474b19cad18aec68ccc7ff76d43067f2dada2e5c2ecd4e535ddbb47bf7e1c15f 970816 openssh-server-dbgsym_9.0p1-1_amd64.ddeb 461a79e8cb33254a28047a4b0705043aa3e48a53d6bb5d5506cb11ac13ebcb40 436046 openssh-server_9.0p1-1_amd64.deb b74671da850082d698767ac354d6cc06e5bebdfa23e89f32bc118d1f81d229bd 114228 openssh-sftp-server-dbgsym_9.0p1-1_amd64.ddeb ac1f5b8746e1a663ea8314dfaff804766329cfc204139f66529b9e9f1bfa74e6 39918 openssh-sftp-server_9.0p1-1_amd64.deb 6ae120c9603223e1e41dee3eb7e15b3fc5b734e66b6c43bed4ad38ab374865e0 1529478 openssh-tests-dbgsym_9.0p1-1_amd64.ddeb 9c7a0d5e5c265fc98d656e414f4daf25bd13fd8acb3078bf631a74e64d661e9e 1417682 openssh-tests_9.0p1-1_amd64.deb 9df1a1b8b10ab0906ac06dd046f1f52e8118866916f30b14a2c5a63c77a69c47 18076 openssh_9.0p1-1_amd64.buildinfo c394ec70078aa29392a266f6302a27e7b902bdc880a464e471ed6bdea8b57d73 8526 openssh_9.0p1-1_amd64_translations.tar.gz c9a9923a253848a20415a88d55d169f0220e1f6b0d3a6f8de3d458de400aab87 17220 ssh-askpass-gnome-dbgsym_9.0p1-1_amd64.ddeb 7cb5bc101a2ddd21859ca6917ac0dadd19853e4a8e51b7fab4240c45a8bcbb32 17982 ssh-askpass-gnome_9.0p1-1_amd64.deb df56cbfe88152358bafdba8fb7b6e02610470fdc0722ef04a4fab28a6751c16c 4832 ssh_9.0p1-1_all.deb Files: ba6101455b0f625bdd2e0bfaa60d7c53 3016756 debug optional openssh-client-dbgsym_9.0p1-1_amd64.ddeb bafa99eac3b43114dba6764640792902 896630 net standard openssh-client_9.0p1-1_amd64.deb 191a6e3de4ee1e73c143c082fd6c4c53 970816 debug optional openssh-server-dbgsym_9.0p1-1_amd64.ddeb bf54b07ef3016850b3c4d728e88ddcab 436046 net optional openssh-server_9.0p1-1_amd64.deb 3b6caf078fb51e80e628abba72f94841 114228 debug optional openssh-sftp-server-dbgsym_9.0p1-1_amd64.ddeb c2904f77fa704842c846b0183c36399c 39918 net optional openssh-sftp-server_9.0p1-1_amd64.deb 08271a173377ae3606506e3c6c9369de 1529478 debug optional openssh-tests-dbgsym_9.0p1-1_amd64.ddeb 5501579377de98ea322238614a0ef0d2 1417682 net optional openssh-tests_9.0p1-1_amd64.deb 26bacdbf62ee676bc59eaee3cb8d6e51 18076 net standard openssh_9.0p1-1_amd64.buildinfo 72b34bbdeb97d7f94c1cceb964f32506 8526 raw-translations - openssh_9.0p1-1_amd64_translations.tar.gz e0d5f0898375336abdb6809bb7a6e345 17220 debug optional ssh-askpass-gnome-dbgsym_9.0p1-1_amd64.ddeb 974b2284c5a14269e54a8ca82a8cace6 17982 gnome optional ssh-askpass-gnome_9.0p1-1_amd64.deb c0aa25c7fc6507dcbef83099b49cf10e 4832 net optional ssh_9.0p1-1_all.deb