package/openssh: security bump to version 8.6p1
authorFabrice Fontaine <fontaine.fabrice@gmail.com>
Sat, 15 May 2021 12:10:35 +0000 (14:10 +0200)
committerYann E. MORIN <yann.morin.1998@free.fr>
Sat, 15 May 2021 15:18:50 +0000 (17:18 +0200)
commit12916827e0d4a31b29031102edf21fe5ab6a2f2a
tree3bedf501903eadc3bf4bfbc5d84fbd50ed97aa3f
parent8a86b50092be19dcc55c4f20c35138d6e378c56b
package/openssh: security bump to version 8.6p1

Security
========

 * sshd(8): OpenSSH 8.5 introduced the LogVerbose keyword. When this
   option was enabled with a set of patterns that activated logging
   in code that runs in the low-privilege sandboxed sshd process, the
   log messages were constructed in such a way that printf(3) format
   strings could effectively be specified the low-privilege code.

   An attacker who had sucessfully exploited the low-privilege
   process could use this to escape OpenSSH's sandboxing and attack
   the high-privilege process. Exploitation of this weakness is
   highly unlikely in practice as the LogVerbose option is not
   enabled by default and is typically only used for debugging. No
   vulnerabilities in the low-privilege process are currently known
   to exist.

https://www.openssh.com/txt/release-8.6

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
package/openssh/openssh.hash
package/openssh/openssh.mk