[arch-dev-public] [signoff] openssh-5.8p2-1
Dear all, An upstream update to openssh is in [testing]; from the Changelog: * Fix local private host key compromise on platforms without host- level randomness support (e.g. /dev/random) reported by Tomas Mraz On hosts that did not have a randomness source configured in OpenSSL and were not configured to use EGD/PRNGd (using the --with-prngd-socket configure option), the ssh-rand-helper command was being implicitly executed by ssh-keysign with open file descriptors to the host private keys. An attacker could use ptrace(2) to attach to ssh-rand-helper and exfiltrate the keys. Most modern operating systems are not vulnerable. In particular, *BSD, Linux, OS X and Cygwin do not use ssh-rand-helper. A full advisory for this issue is available at: http://www.openssh.com/txt/portable-keysign-rand-helper.adv There are other minor changes but they don't concern Arch. Please test and signoff. -- Gaetan
On 03/05/11 12:23, Gaetan Bisson wrote:
Please test and signoff.
I can still ssh into stuff... but I don't run a server that can be ssh'ed into at the moment so this is only a part test. Partial signoff for i686, Allan
Am Dienstag 03 Mai 2011 schrieb Allan McRae:
On 03/05/11 12:23, Gaetan Bisson wrote:
Please test and signoff.
I can still ssh into stuff... but I don't run a server that can be ssh'ed into at the moment so this is only a part test.
Partial signoff for i686, Allan signoff both
-- Tobias Powalowski Archlinux Developer & Package Maintainer (tpowa) http://www.archlinux.org tpowa@archlinux.org
On Tue, May 3, 2011 at 6:11 PM, Tobias Powalowski <t.powa@gmx.de> wrote:
Am Dienstag 03 Mai 2011 schrieb Allan McRae:
On 03/05/11 12:23, Gaetan Bisson wrote:
Please test and signoff.
I can still ssh into stuff... but I don't run a server that can be ssh'ed into at the moment so this is only a part test.
Partial signoff for i686, Allan signoff both
signoff x86_64
On 05/04/2011 01:23 PM, Tom Gundersen wrote:
On Tue, May 3, 2011 at 6:11 PM, Tobias Powalowski<t.powa@gmx.de> wrote:
Am Dienstag 03 Mai 2011 schrieb Allan McRae:
On 03/05/11 12:23, Gaetan Bisson wrote:
Please test and signoff.
I can still ssh into stuff... but I don't run a server that can be ssh'ed into at the moment so this is only a part test.
Partial signoff for i686, Allan signoff both
signoff x86_64
signoff i686 -- Ionuț
participants (5)
-
Allan McRae
-
Gaetan Bisson
-
Ionut Biru
-
Tobias Powalowski
-
Tom Gundersen